blog-ssm icon indicating copy to clipboard operation
blog-ssm copied to clipboard

发现几处安全问题

Open By-Yexing opened this issue 1 year ago • 0 comments

1.两处文件上传绕过: 由于在代码中采用了黑名单过滤后缀“.jsp”和“.asp”,攻击者可以利用windows自动去除后缀“.”,"::$DATA”等,来进行绕过。如下: /uploadFileList 接口: 代码分析: 1705369861116 1705369868122 漏洞复现: 1705369825775 1705369840162 /upFile 接口: 代码分析: 1705369915142 1705369918042 1705369921808 1705369924377 漏洞复现: 1705370134198 1705370140909

建议修复方案:采用白名单防御,仅允许上传.txt,.zip,.png,.mp3等常见后缀,禁止上传脚本格式,,如:.html(可导致产生存储型XSS),.jsp,.jspx, .php .asp等,可导致代码执行!!!

2.两处SQL注入,由于采用了"${"的方式进行拼接,所以导致产生SQL注入问题,如下: 漏洞产生位置: com/rawchen/mapper/ContentMapper.xml: 1705370443868 com/rawchen/mapper/TagMapper.xml: image 漏洞复现: 1705370513961 image image image

建议修复方案: 1705370283022

By-Yexing avatar Jan 16 '24 02:01 By-Yexing