Ê©ÄÍµÂµçÆøU.Motion BuilderÏÂÁî×¢ÈëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-05-22Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2018-7841£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º9.8
Ó°Ïì°æ±¾
Schneider Electric U.Motion Builder 1.3.4¼°Ö®Ç°°æ±¾
Îó²î¸ÅÊö
Schneider Electric U.Motion Builder 1.3.4¼°Ö®Ç°°æ±¾ÖеÄtrack_import_export.php¾ç±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÏÂÁîµÈ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
CVE-2018-7841ΪCVE-2018-7765²¹¶¡Èƹý£¬£¬£¬£¬£¬£¬£¬£¬U.Motion 1.3.4°üÀ¨Ò×Êܹ¥»÷µÄÎļþ/smartdomuspad/modules/reporting/track_import_export.php£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÓ¦ÓóÌÐòƾ֤ÅþÁ¬µÄobject_id½á¹¹Ò»¸öÃûΪ$ whereµÄSQliteÅÌÎÊ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÅÌÎÊ¿ÉÒÔͨ¹ýGET»òPOSTÌṩ£º
Äã¿ÉÒÔ¿´µ½object_idÊ×Ïȱ»string_encode_for_SQLiteÒªÁìÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬³ýÁËɾ³ýһЩÆäËû²»¿É¶ÁµÄ×Ö·û£º
$ queryÖ®ºóÓÃÓÚŲÓÃ$ dbClient-> query£¨£©£º
query£¨£©ÒªÁì¿ÉÒÔÔÚdpaddbclient_NoDbManager_sqlite.class.phpÖÐÕÒµ½£º
ÔÚÕâÀ£¬£¬£¬£¬£¬£¬£¬Äú¿ÉÒÔ¿´µ½ÅÌÎÊ×Ö·û´®£¨°üÀ¨object_id£©ÊÇͨ¹ýÒ»¶Ñstr_replaceŲÓÃÌṩµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ä¿µÄÊǹýÂ˵ôΣÏÕ×Ö·û£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈç$ for UnixÏÂÁîÌæ»»£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÆ¬¶Ïĩ⣬£¬£¬£¬£¬£¬£¬£¬ÄúÏÖʵÉÏ¿ÉÒÔ¿´µ½ ÁíÒ»¸ö×Ö·û´®$ sqlite_cmdÓëÏÈǰ¹¹½¨µÄ$ query×Ö·û¹´Í¨½Ó£¬£¬£¬£¬£¬£¬£¬£¬×îºóת´ï¸øPHP exec£¨£©Å²Óᣡ£¡£¡£¡£
±¬·¢Ò»¸öƯÁÁµÄ·´Ïòshell£º
ÐÞ¸´½¨Òé
https://www.rcesecurity.com/
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ