当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2014-081010

漏洞标题:浙江联众医院建站系统网站 + 外网管理后台两处SQL注入

相关厂商:浙江联众智慧科技股份有限公司

漏洞作者: 小饼仔

提交时间:2014-10-30 11:37

修复时间:2015-01-28 11:38

公开时间:2015-01-28 11:38

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2014-10-30: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-01-28: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

之前有人发过这个厂商的洞,厂商貌似不管?

详细说明:

之前几个该系统的漏洞,貌似会被厂商忽略,审核还是给cncert吧
WooYun: 某医院建站系统通用型SQL注入漏洞 注册验证用户名SQL注入
WooYun: 浙江联众为多家医院建设的信息门户网站SQL注入漏洞 inurl:cms/Column.aspx?LMID= SQL注入
WooYun: 浙江联众智慧科技医院建站系统任意文件上传漏洞 任意文件上传
上面三个洞都是走大厂商,我这个应该也是吧?
这里发现两处新的注入
一. inurl:/cms/Article.aspx?NRID=

google.jpg


NRID参数存在注入
除部分网站有WAF不能注入外,其他都可以
这里列出几个可以注入的例子:
http://www.zchospital.com/cms/Article.aspx?NRID=12774&LMID=47
http://www.zjhl.org/cms/article.aspx?nrid=446&lmid=125
http://ywzxyy.com/cms/Article.aspx?NRID=10000131&LMID=41
http://sig.cem.org.cn/cms/Article.aspx?NRID=16525&LMID=29
http://www.hnzyy.cn/cms/Article.aspx?NRID=12541&LMID=105
http://oa.ywwsj.gov.cn/oa/cms/article.aspx?nrid=2853
http://www.zjqhyy.com/cms/article.aspx?nrid=13125&lmid=24
http://www.z2hospital.com/cms/Article.aspx?NRID=13440&LMID=153
证明:
1. http://www.zchospital.com/cms/Article.aspx?NRID=12774&LMID=47

11.jpg


2. http://www.zjhl.org/cms/article.aspx?nrid=446&lmid=125

12.jpg


3. http://sig.cem.org.cn/cms/Article.aspx?NRID=16525&LMID=29

13.jpg


4. http://www.z2hospital.com/cms/Article.aspx?NRID=13440&LMID=153

14.jpg


二:第二处是医院外网管理后台,登入界面POST参数zggh注入
大多数都是网站地址 + /login.aspx
登陆界面都类似,比如
1. 义乌市中心医院

211.jpg


2. 浙江省口腔医院

212.jpg


3. 浙江省立同德医院

213.jpg


举例:
萧山医院--医院综合管理平台 http://www.zjxsh.com/oa/login.aspx
义乌市中心医院 http://ywzxyy.com/login.aspx
浙江省护理中心 http://www.zjhl.org/hlzk/login.aspx
浙江省肿瘤医院 http://www.zchospital.com/login.aspx
浙江省口腔医院 http://www.zjkq.com.cn/login.aspx
浙江大学医学院附属第二医院 http://sig.cem.org.cn/login.aspx
海宁市中医院 http://www.hnzyy.cn/login.aspx
富阳市人民医院 http://www.fysrmyy.com/login.aspx
浙江衢化医院 http://www.zjqhyy.com/login.aspx
浙江省立同德医院 http://www.zjtongde.net/login.aspx
证明:
1. 萧山医院--医院综合管理平台 http://www.zjxsh.com/oa/login.aspx
post请求:

POST /oa/login.aspx HTTP/1.1
Host: www.zjxsh.com
Proxy-Connection: keep-alive
Content-Length: 285
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: http://www.zjxsh.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.143 Safari/537.36
Content-Type: application/x-www-form-urlencoded
DNT: 1
Referer: http://www.zjxsh.com/oa/login.aspx
Accept-Encoding: gzip,deflate,sdch
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: ASP.NET_SessionId=eyavhw55yptt0d45yz3i1uix
RA-Ver: 2.7.0
RA-Sid: 65E7C870-20141014-044958-a23ba1-b78bcc
__LASTFOCUS=&__EVENTTARGET=btnOK&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwUKLTE0MjEzNjc5M2QYAQUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgEFBWp6eWhtLuNDrUyrzc8fuLP4On9UTyBAj9Y%3D&zggh=a&dlkl=a&__EVENTVALIDATION=%2FwEWBQK26L%2BaDgKd1YqTBwK%2F5oCoCgKk89r0AQLdkpmPAUrx73UIvOPCpzIVe3KIgLTiojLo


221.jpg


2. 浙江大学医学院附属第二医院 http://sig.cem.org.cn/login.aspx
post请求

POST /login.aspx HTTP/1.1
Host: sig.cem.org.cn
Proxy-Connection: keep-alive
Content-Length: 291
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: http://sig.cem.org.cn
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.143 Safari/537.36
Content-Type: application/x-www-form-urlencoded
DNT: 1
Referer: http://sig.cem.org.cn/login.aspx
Accept-Encoding: gzip,deflate,sdch
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: ASP.NET_SessionId=eoyb0o45yhsrj5553bsvhm3b
RA-Ver: 2.7.0
RA-Sid: 65E7C870-20141014-044958-a23ba1-b78bcc
__LASTFOCUS=&__EVENTTARGET=btnOK&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwUJNzE3ODI3MDUxZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAQUFanp5aG3rxRMnAcW2frXFoeEmR6WrSM2ztA%3D%3D&__EVENTVALIDATION=%2FwEWBQLqnbCmAQKd1YqTBwK%2F5oCoCgKk89r0AQLdkpmPAcLJYDP%2B3pQZaStVPeudgcNHjm%2Be&zggh=aa&dlkl=aa


222.jpg


3. 浙江衢化医院 http://www.zjqhyy.com/login.aspx
post请求

POST /login.aspx HTTP/1.1
Host: www.zjqhyy.com
Proxy-Connection: keep-alive
Content-Length: 293
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: http://www.zjqhyy.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.143 Safari/537.36
Content-Type: application/x-www-form-urlencoded
DNT: 1
Referer: http://www.zjqhyy.com/login.aspx
Accept-Encoding: gzip,deflate,sdch
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: ASP.NET_SessionId=lt0m0vfmpfigmw45rxcyznqy
RA-Ver: 2.7.0
RA-Sid: 65E7C870-20141014-044958-a23ba1-b78bcc
__LASTFOCUS=&__EVENTTARGET=btnOK&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwUJNzE3ODI3MDUxZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAQUFanp5aG18OLy7P5jNxNLT13XZliKo3hh7qA%3D%3D&__EVENTVALIDATION=%2FwEWBQKohr%2BNBwKd1YqTBwK%2F5oCoCgKk89r0AQLdkpmPAQqf4I5rFhAOS34%2FH%2FInxOlpHCky&zggh=aa&dlkl=aa


223.jpg


4. 浙江省护理中心 http://www.zjhl.org/hlzk/login.aspx
post请求

POST /hlzk/login.aspx HTTP/1.1
Host: www.zjhl.org
Proxy-Connection: keep-alive
Content-Length: 347
Cache-Control: max-age=0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Origin: http://www.zjhl.org
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.143 Safari/537.36
Content-Type: application/x-www-form-urlencoded
DNT: 1
Referer: http://www.zjhl.org/hlzk/login.aspx
Accept-Encoding: gzip,deflate,sdch
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.6,en;q=0.4
Cookie: ASP.NET_SessionId=loyjne2fi4hl01wsglcepank
RA-Ver: 2.7.0
RA-Sid: 65E7C870-20141014-044958-a23ba1-b78bcc
__LASTFOCUS=&__EVENTTARGET=btnOK&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwUJNzE3ODI3MDUxZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAQUFanp5aG2lkKp8OjHPFtkQbxtSbfIkXOQyfiV2gXUpVbFkT2ff1g%3D%3D&__VIEWSTATEGENERATOR=70EB98A2&__EVENTVALIDATION=%2FwEWBQK5vpzZCwKd1YqTBwK%2F5oCoCgKk89r0AQLdkpmPAeNbPjfYo8Z07mT7dGBJbwQ6Bd7fGEI87uPotRO2CdlS&zggh=a&dlkl=a


224.jpg

漏洞证明:

修复方案:

~

版权声明:转载请注明来源 小饼仔@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝