Ê©ÄÍµÂµçÆøU.Motion BuilderºÅÁî×¢Èë·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-05-22·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-7841£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
Schneider Electric U.Motion Builder 1.3.4¼°Ö®Ç°°æ±¾
·ì϶¸ÅÊö
Schneider Electric U.Motion Builder 1.3.4¼°Ö®Ç°°æ±¾ÖеÄtrack_import_export.php¾ç±¾ÖдæÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ±í²¿ÊäÈëÊý¾Ý»ú¹Ø²Ù×÷ϵͳ¿ÉÖ´ÐкÅÁî¹ý³ÌÖУ¬ÍøÂçϵͳ»ò²úƷδÕýÈ·¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ºÅÁîµÈ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨²Ù×÷ϵͳºÅÁî¡£
·ì϶ÑéÖ¤
CVE-2018-7841ΪCVE-2018-7765²¹¶¡Èƹý£¬U.Motion 1.3.4Ô̺¬Ò×Êܹ¥»÷µÄÎļþ/smartdomuspad/modules/reporting/track_import_export.php£¬ÆäÖÐÀûÓ÷¨Ê½Æ¾¾ÝÏνӵÄobject_id»ú¹ØÒ»¸öÃûΪ$ whereµÄSQlite²éÎÊ£¬¸Ã²éÎÊÄܹ»Í¨¹ýGET»òPOSTÌṩ£º
ÄãÄܹ»¿´µ½object_idÊ×Ïȱ»string_encode_for_SQLite²½Öè½âÎö£¬³ýÁËɾ³ýһЩÆäËû²»³É¶ÁµÄ×Ö·û£º
$ queryÖ®ºóÓÃÓÚŲÓÃ$ dbClient-> query£¨£©£º
query£¨£©²½ÖèÄܹ»ÔÚdpaddbclient_NoDbManager_sqlite.class.phpÖÐÕÒµ½£º
ÔÚÕâÀÄúÄܹ»¿´µ½²éÎÊ×Ö·û´®£¨Ô̺¬object_id£©ÊÇͨ¹ýÒ»¶Ñstr_replaceŲÓÃÌṩµÄ£¬Ö÷ÕÅÊǹýÂ˵ôΣÏÕ×Ö·û£¬ÀýÈç$ for UnixºÅÁî´úÌæ£¬²¢ÇÒÔÚÆ¬¶Îĩ⣬ÄúÏÖʵÉÏÄܹ»¿´µ½ ÁíÒ»¸ö×Ö·û´®$ sqlite_cmdÓëÏÈǰ¹¹½¨µÄ$ query×Ö·û´®Ïνӣ¬×îºó´«µÝ¸øPHP exec£¨£©Å²Óá£
²úÉúÒ»¸öÃÀÀöµÄ·´Ïòshell£º
½¨¸´½¨Òé
https://www.rcesecurity.com/
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ