ECShopÔ¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-09-04Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ECShop 2.x¡¢ECShop 3.x
Îó²î¸ÅÊö
ECShopÊÇÒ»¿îB2C×ÔÁ¦Íøµêϵͳ£¬ÊÊºÏÆóÒµ¼°Ð¡ÎÒ˽¼Ò¿ìËÙ¹¹½¨¸öÐÔ»¯ÍøÉÏÊÐËÁ¡£ÏµÍ³ÊÇ»ùÓÚPHPÓïÑÔ¼°MySQLÊý¾Ý¿â¹¹¼Ü¿ª·¢µÄ¿çƽ̨¿ªÔ´³ÌÐò¡£¸ÃÍøµêϵͳ´ó×ÚÓÃÓÚСÎÒ˽¼ÒÍøµê´î½¨¡£ECShop¿ª·¢Á˶ÀÍ̵ĸßЧģ°åÒýÇæ(2.15ÒÔǰ°æ±¾Ê¹ÓÃsmartyÄ£°åÒýÇæ)£¬²¢ÍŽáÁËDreamweaverµÄÄ£°åºÍ¿â¹¦Ð§£¬Ê¹µÃ±à¼ÖÆ×÷Ä£°å±äµÃ¸ü¼òÆÓ¡£Óû§¿Éƾ֤×Ô¼ºµÄÐèÇó¶ÔECShop¾ÙÐж¨ÖƺÍÀ©Õ¹¡£
¸ÃÎó²î±¬·¢µÄ»ù´¡Ôµ¹ÊÔÓÉÔÚÓÚECShopϵͳµÄuser.phpÎļþÖУ¬displayº¯ÊýµÄÄ£°å±äÁ¿¿É¿Ø£¬µ¼ÖÂ×¢È룬ÅäºÏ×¢Èë¿ÉµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄЧ¹û¡£Ê¹µÃ¹¥»÷ÕßÎÞÐèµÇ¼µÈ²Ù×÷£¬Ö±½Ó¿ÉÒÔ»ñµÃ·þÎñÆ÷µÄȨÏÞ¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ±½Ó»ñÈ¡µ½·þÎñÆ÷µÄ×î¸ßȨÏÞ¡£¸ÃÎó²îÓ°ÏìECShopȫϵÁа汾£¬×èÖ¹ÏÖÔÚ£¬¹Ù·½ÉÐδÐû²¼¹ØÓÚÎó²îµÄÐÂÎż°²¹¶¡£¬ÏÖ½×¶ÎʹÓøÃÎó²îʵÑéÅúÁ¿»¯¹¥»÷µÄÊýÄ¿Õý³ÊÉÏÉýÇ÷ÊÆ¡£
Îó²îÑéÖ¤
½Ó×Å£¬$back_act±äÁ¿±»assignº¯ÊýŲÓã¬assignº¯ÊýÓÃÓÚ½«Íⲿ±äÁ¿×ª´ï¸øÄ£°åº¯Êý£¬È»ºóͨ¹ýdisplayº¯Êý½«Ö®ÏÔʾÔÚÒ³ÃæÉÏ¡£
ÔÚ/include/cls_template.phpÎļþÖÐÕÒµ½displayº¯Êý£¬¸Ãº¯ÊýÖÐÓÐÒ»¸öinsert_modº¯ÊýÊÇÒªº¦¡£
insert_modº¯ÊýÔÚ1150ÐУ¬¸Ãº¯Êý·µ»ØÒ»¸ö¶¯Ì¬Å²Óã¬Æ¾Ö¤PoCµÄϸ½Ú£¬ÎÒÃÇ¿ÉÒÔµÃ֪ŲÓõĺ¯ÊýÃûÊÇinsert_ads¡£
¸ú½øinsert_adsº¯Êý£¬¸Ãº¯Êý±£´æÓÚ/include/lib_insert.phpÎļþÖÐ:
¿ÉÒÔ´ÓPoCÖз¢Ã÷£¬$arr['id']ºÍ$arr['num']ÕâÁ½¸ö±äÁ¿£¬¶¼ÊÇÍⲿ¿É¿ØµÄÊäÈëµã£¬Ôڽṹ¹¥»÷ÏòÁ¿µÄÀú³ÌÖÐÓÃÓÚÖ´ÐÐSQLÓï¾ä¡£¶øÔÚº¯ÊýµÄ×îºó£¬Å²ÓÃÁËfetchº¯Êý£¬¸Ãº¯ÊýÊÇ´úÂëÖ´ÐÐÖÐÎó²î´¥·¢µÄµã¡£
Ê×ÏÈÆ¾Ö¤ÌáÐÑ×°ÖúÃECShopÇéÐÎ(2.7.3°æ±¾)£¬È»ºó¸´ÏÖ¸ÃÎó²î£¬Í¨¹ýBrup Suite×¥°üÐÂÔöReferer×Ö¶ÎÒÔ¼°Payloadºó£¬»ñµÃÏìÓ¦°ü£¬¸´ÏÖ¸ÃÎó²î£¬ÔÚÏìÓ¦Ò³ÃæÀֳɴòÓ¡³öSQLÓï¾ä¡£
È»ºóʹÓÃSQL×¢ÈëÎó²î£¬À´¸´ÏÖдÈëwebshellµÄ²Ù×÷£¬Ê×Ïȹ¥»÷ͬÑùÊÇÐÞ¸ÄReferer×Ö¶ÎÖеÄÖµ£¬¼ÓÈë½á¹¹ºÃµÄPoC£¬ÓÃSQLÓï¾ä¾ÙÐÐÏÂÁî×¢Èë¡£¿ÉÒÔ¿´µ½×îÖÕÔÚ¸ùĿ¼ÏÂÌìÉúÁËwebshell£¬webshellΪ1.phpÎļþ¡£
Ó°Ïì¹æÄ£
ÐÞ¸´½¨Òé
ÔÝʱ´¦Öóͷ£·½·¨¿ÉÒÔÐÞ¸Äinclude/lib_insert.phpÎļþÖÐÏà¹ØÎó²îµÄ´úÂ룬½«$arr[id]ºÍ$arr[num]Ç¿ÖÆ½«Êý¾Ýת»»³ÉÕûÐÍ£¬$arr[id]ºÍ$arr[num]ǰ¼ÓÈëintvalÏÞÖÆ¡£ÐèÒªÐ޸ĵĵط½Îª£º
ECShop 3.6.0ÐÞ¸´ÁËÒÔÉÏÎó²î£¬Òò´Ë½¨Ò龡¿ì¸üÐÂÖÁ×îеÄ3.6.0°æ±¾¡£
http://ringk3y.com/2018/08/31/ecshop2-x%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C/


¾©¹«Íø°²±¸11010802024551ºÅ