¡¾Îó²îͨ¸æ¡¿·ºÎ¢e-cology SQL×¢ÈëÎó²î£¨CVE-2023-3793£©

Ðû²¼Ê±¼ä 2023-07-21



Ò»¡¢Îó²î¸ÅÊö

CVE   ID

CVE-2023-3793

·¢Ã÷ʱ¼ä

2023-07-21

Àà    ÐÍ

SQL×¢Èë

µÈ    ¼¶

ÖÐΣ

¹¥»÷ÏòÁ¿

ÍâµØÍøÂç

ËùÐèȨÏÞ

µÍ

¹¥»÷ÖØÆ¯ºó

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

±£´æ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

·ºÎ¢Ð­Í¬ÖÎÀíÓ¦ÓÃÆ½Ì¨£¨e-cology£©ÊÇÒ»Ì×¼æ¾ßÆóÒµÐÅÏ¢ÃÅ»§¡¢ÖªÊ¶ÖÎÀí¡¢Êý¾ÝÖÐÐÄ¡¢ÊÂÇéÁ÷ÖÎÀí¡¢ÈËÁ¦×ÊÔ´ÖÎÀí¡¢¿Í»§ÓëÏàÖúͬ°éÖÎÀí¡¢ÏîÄ¿ÖÎÀí¡¢²ÆÎñÖÎÀí¡¢×ʲúÖÎÀí¹¦Ð§µÄЭͬÉÌÎñƽ̨¡£¡£¡£

7ÔÂ21ÈÕ£¬£¬ £¬£¬£¬£¬£¬918²©ÌìÌÃVSRC¼à²âµ½·ºÎ¢e-cology±£´æÒ»¸öSQL×¢ÈëÎó²î£¨CVE-2023-3793£©£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²îµÄCVSSÆÀ·ÖΪ5.5¡£¡£¡£

·ºÎ¢e-cology°æ±¾10.58.0֮ǰ±£´æSQL×¢ÈëÎó²î£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²îÓ°ÏìHTTP POST ÇëÇó´¦Öóͷ£³ÌÐò×é¼þµÄfilelFileDownloadForOutDoc.class ÎļþµÄijЩδ֪´¦Öóͷ££¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃÊäÈë1+WAITFOR+DELAY²Ù×÷²ÎÊýfileid»áµ¼ÖÂSQL×¢È룬£¬ £¬£¬£¬£¬£¬¿ÉʹÓøÃÎó²î»ñÈ¡Êý¾Ý¿âÖеÄÃô¸ÐÐÅÏ¢²¢½øÒ»²½Ö´ÐжñÒâ²Ù×÷¡£¡£¡£

 

¶þ¡¢Ó°Ïì¹æÄ£

·ºÎ¢e-cology°æ±¾<10.58.0

 

Èý¡¢Çå¾²²½·¥

3.1 Éý¼¶°æ±¾

ÏÖÔÚ¹Ù·½ÒѾ­ÐÞ¸´Á˸ÃÎó²î£¬£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½ÒÔϰ汾£º

·ºÎ¢e-cology°æ±¾>=10.58.0

ÏÂÔØÁ´½Ó£º

https://www.weaver.com.cn/cs/securityDownload.asp#

3.2 ÔÝʱ²½·¥

ÔÝÎÞ¡£¡£¡£

3.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ £¬£¬£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ £¬£¬£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬ £¬£¬£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬ £¬£¬£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ £¬£¬£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ £¬£¬£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ £¬£¬£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ £¬£¬£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬ £¬£¬£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£

3.4 ²Î¿¼Á´½Ó

https://nvd.nist.gov/vuln/detail/CVE-2023-3793

https://vuldb.com/?id.235061 

ËÄ¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2023-07-21

Ê×´ÎÐû²¼

 

Îå¡¢¸½Â¼

5.1 918²©ÌìÌüò½é

918²©ÌìÌý¨ÉèÓÚ1996Ä꣬£¬ £¬£¬£¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°918²©ÌìÌôóÏ㬣¬ £¬£¬£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬ £¬£¬£¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ £¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬ £¬£¬£¬£¬£¬918²©ÌìÌÃÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬ £¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬ £¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£

5.2 ¹ØÓÚ918²©ÌìÌÃ

918²©ÌìÌÃÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬ £¬£¬£¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬ £¬£¬£¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png