用友NC cartabletimeline/doList SQL注入漏洞


漏洞简介

用友NC系统的 cartabletimeline/doList 接口存在SQL注入漏洞。攻击者可通过构造恶意的 SQL 语句注入请求参数,绕过身份验证或获取数据库敏感信息,进而可能导致任意数据读取、篡改甚至系统权限提升,影响系统的安全性和数据完整性。

影响版本

NC65

fofa语法

app="用友-UFIDA-NC"

漏洞分析

直接看VsmAction 类的doList方法的实现逻辑吧

@Servlet(
    path = "/cartabletimeline"
)
public class VsmAction extends BaseAction {
    @Action
    public void doList() {
        HttpServletRequest request = this.request;
        String pks = request.getParameter("mtr");
        StringBuilder sd = new StringBuilder();
        sd.append("<?xml version='1.0' encoding='UTF-8' ?>");
        ICarTalbeService carTalbeService = (ICarTalbeService)NCLocator.getInstance().lookup(ICarTalbeService.class);
        StringBuffer sb = new StringBuffer();
        sb.append("(").append(pks).append(")");
        ApplyVO[] applyVOs = null;
        PersonVO[] personVOS = null;
        Map<String, PersonVO> personMap = new HashMap();

        try {
            applyVOs = carTalbeService.getVehicleApplyInfo((String)null, sb.toString(), (PaginationInfo)null);
            sd.append("<data>");

跟进ICarTalbeService的getVehicleApplyInfo方法

public ApplyVO[] getgetUserVehicleApplyInfo(String pkUser, String whereSql, PaginationInfo pageInfo) throws LfwBusinessException {
    ApplyVO applyVOs = new ApplyVO();
    StringBuilder sb = new StringBuilder();
    if (!StringUtils.isBlank(whereSql)) {
        sb.append(" ( billstatus = 5 or billstatus = 6 ) and dispatchvehicle in  ").append(whereSql);
    }

    return (ApplyVO[])CRUDHelper.getCRUDService().queryVOs(applyVOs, pageInfo, sb.toString(), (Map)null, (String)null);
}

参数mtr这里被拼接进SQL语句中,整个过程没有对参数mtr进行校验或过滤,从而造成了SQL注入漏洞,朴实无华的!

漏洞复现

需注意NC 大多数为Oracle 少数MSSQL

POST /portal/pt/cartabletimeline/doList HTTP/1.1
Host: nc.mrxn.net
Content-Type: application/x-www-form-urlencoded

pageId=login&meapk=SQLI_POC

成功延时 3 秒


手机扫码阅读

西部数码 NAS php/sendLogToSupport.php 命令执行漏洞

亿赛通-电子文档安全管理系统 DecryptApplication 多个文件读取漏洞

评 论