phpMyAdminÔ¶³ÌÖ´ÐдúÂë·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2018-07-03·ì϶±àºÅºÍ¼¶±ð
Ó°ÏìÁìÓò
ÊÜÓ°ÏìµÄϵͳ°æ±¾£º
phpMyAdmin 4.8.1
·ì϶¸ÅÊö
phpMyAdmin ÊÇÒ»¸öÒÔPHPΪ»ù´¡£¬ÒÔWeb-Base·½Ê½¼Ü¹¹ÔÚÍøÕ¾Ö÷»úÉϵÄMySQLµÄÊý¾Ý¿âÖÎÀí¹¤¾ß£¬ÈÃÖÎÀíÕß¿ÉÓÃWeb½Ó¿ÚÖÎÀíMySQLÊý¾Ý¿â¡£
ÔÚphpMyAdmin 4.8.x°æ±¾ÖУ¬·¨Ê½Ã»ÓÐÑϸñ½ÚÔìÓû§µÄÊäÈ룬¹¥»÷ÕßÄܹ»ÀûÓÃË«³Á±àÂëÈÆ¹ý·¨Ê½µÄ°×Ãûµ¥ÏÞ¶È£¬Ôì³ÉÎļþÔ̺¬·ì϶¡£
´Ë·ì϶ʹ¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÄÜÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâPHP´úÂë¡£
phpMyAdminµÄ¹úÄÚÊý¾Ýͳ¼ÆÍ¼ÈçÏ£º
·ì϶·ÖÎö
ÔÚ/index.php
ÕâÀïµÄtarget Äܹ»Ö±½Ó´«ÖµÊäÈë¡£ÎÒÃÇÄܹ»´«ÈëÒ»¸ö±¾µØÎļþõè¾¶È¥ÈÃÆäÔ̺¬£¬¾Í»áÔì³ÉLFI·ì϶¡£
Ê×ÏÈ£¬ÎÒÃÇÂú×ã4¸öǰÌ᣺
2£®²»ÄÜÒÔ/index/ ¿ªÍ·¡£
3£®²»ÄÜÔÚ$target_blacklistÊý×éÄÚ¡£
¸ú×ÙÒ»ÏÂcheckPageValidityº¯Êý
ÔÚ/libraries/classes/Core.php
¸Ãº¯ÊýÄÚ£¬ÓÐÈý´¦·µ»ØtureµÄ´¦Ëù£¬Ö»ÓÐÓÐËÁÒâÒ»´¦·µ»Øture¾ÍÄܹ»¡£¹Û²ìÕâÈý´¦£¬ÓÐÒ»¸ö¹²Í¬µã£¬¶¼ÊDZØÒª$pageÔÚ$whitelistÊý×éÖÐÄڲŻ᷵»Øtrue¡£
ÎÒÃÇÏÈ¿´µÚÒ»¸ö·µ»ØtrueµÄ´¦Ëù¡£

ÕâÀïµÄ$pageÔÚin_array֮ǰûÓо¹ýÈκεĽ¨ÊΣ¬Ö±½Ó¾ÍÓë$whitelist×÷±ÈÁ¦¡£Ã»Óз¨×ÓÈÆ¹ý£¬´«ÈëµÄtargetÖµÖ»ÄÜΪ°×Ãûµ¥ÀïµÄÎļþÃû²ÅÐС£ºÜÏÔÖø£¬µÚÒ»¸ö²¢²»ÄÜÀûÓá£
ÔÙÀ´¿´µÚ¶þ¸ö

ÏȽéÉÜÏÂÕâЩº¯ÊýµÄ×÷Óãº
mb_strpos()º¯ÊýµÄÒâ˼ÊDzéÕÒ×Ö·û´®ÔÚÁíÒ»¸ö×Ö·û´®Öгõ´Î³öÏֵĵØÎ»¡£
mb_substr()º¯ÊýµÄÒâ˼ÊÇ£º
´Ó$str×Ö·û´®ÖУ¬ÌáÈ¡´Ó$startµØÎ»ÆðÍ·£¬³¤¶ÈΪ$lengthµÄ×Ö·û´®¡£
Äܹ»¿´³ö£¬µÚ¶þ¸öÄܹ»·µ»Øture£¬ÎÒÃÇÀûÓÃdb_sql.php?/../../Ìåʽ¾ÍÄܹ»´ïµ½Ö÷ÕÅ£¬Èƹý°×Ãûµ¥ÏÞ¶È¡£ÄÇÊDz»ÊÇÕâÑù¾ÍÄܹ»Ôì³É·ì϶ÁËÄØ£¿
Èç¹ûÎÒÃÇÓÃdb_sql.php?/../../../aaa.txtÀ´Èƹý°×Ãûµ¥Ï޶ȽøÐÐÔ̺¬Îļþ¡£

ÄÇÕâÀï¾ÍÊÇ include ¡®db_sql.php?/../../../aaa.txt¡¯¡£
ÕâÖÖÌåʽ²¢²»ÄÜ¿çõè¾¶Ô̺¬£¬ÓÉÓÚphp·¨Ê½°Ñ£¿ºÅºóÃæµÄÆ÷²Äµ±³ÉÊÇ´«Èëdb_sql.phpÎļþµÄ²ÎÊý¡£
ÔÙÀ´¿´µÚÈý¸ö£º

µÚÈý¸öºÍµÚ¶þ¸ö¶Ô±È¶à³öÁ˸öurldecode()º¯Êý¡£
¶øÎÊÌâ¸ÕºÃ³öÔÚÁËÕâ¸öurldecode()º¯Êý¡£
ÔÒòÊÇ£º
%253f ´«Èëʱ£¬Ê×ÏȻᱻ×Ô¶¯½âÂëÒ»´Î£¬Ôì³É%3f¡£¶øºóurldecode()ÔÙ½âÂëÒ»´Î£¬¾ÍÔì³ÉÁË ?¡£ ³É¹¦ÈƹýÁ˰×Ãûµ¥ÏÞ¶È¡£
ÕâÖÖÇé¿öÏÂincludeµÄÔ̺¬Çé¿ö¾ÍÊÇÕâÑùµÄ£¬Ò²¾ÍÄܹ»ËÁÒâÔ̺¬±¾µØÎļþÁË¡£
·ì϶ÀûÓÃ
ÆëÈ«µÄexp£º
tips£º
1¡¢%3f ½«±»½âÂë²¢³ÉΪ?¡£
2¡¢Core::checkPageValidity°þÀëËùÓÐÄÚÈÝ?²¢sql.phpÔÚ°×Ãûµ¥ÄÚÕÒµ½£º²é³±»Èƹý£¡3¡¢index.phpÔËÐÐinclude 'sql.php?/../../etc/passwd'£¬PHPµÄħÊõÀ´×ª»»õè¾¶ ../etc/passwd£¬¶ø²»²é³Ä¿Â¼ÊÇ·ñsql.php?´æÔÚ¡£×îºó£¬ËüÔ̺¬../etc/passwd³É¹¦¡£
ҪдÕâ¸ö·ì϶£¬Äܹ»Ã¶¾ÙÎļþõè¾¶£¬È磺
/etc/passwd
../../etc/passwd../windows/win.ini
../../windows/win.ini
½¨¸´½¨Òé
Ŀǰ¹Ù·½Òѽ¨¸´¸Ã·ì϶£¬°ä²¼ÁË×îа汾4.8.2£¬¿É´Ó¹ÙÍøÏÂÔØ×îа汾¡£
²Î¿¼Á´½Ó
https://www.securityfocus.com/bid/104532
https://nvd.nist.gov/vuln/detail/CVE-2018-12613


¾©¹«Íø°²±¸11010802024551ºÅ