phpMyAdminÔ¶³ÌÖ´ÐдúÂëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-03Îó²î±àºÅºÍ¼¶±ð
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄϵͳ°æ±¾£º
phpMyAdmin 4.8.1
Îó²î¸ÅÊö
phpMyAdmin ÊÇÒ»¸öÒÔPHPΪ»ù´¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬ÒÔWeb-Base·½·¨¼Ü¹¹ÔÚÍøÕ¾Ö÷»úÉϵÄMySQLµÄÊý¾Ý¿âÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬ÈÃÖÎÀíÕß¿ÉÓÃWeb½Ó¿ÚÖÎÀíMySQLÊý¾Ý¿â¡£¡£¡£¡£¡£
ÔÚphpMyAdmin 4.8.x°æ±¾ÖУ¬£¬£¬£¬£¬£¬³ÌÐòûÓÐÑÏ¿á¿ØÖÆÓû§µÄÊäÈ룬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃË«ÖØ±àÂëÈÆ¹ý³ÌÐòµÄ°×Ãûµ¥ÏÞÖÆ£¬£¬£¬£¬£¬£¬Ôì³ÉÎļþ°üÀ¨Îó²î¡£¡£¡£¡£¡£
´ËÎó²îʹ¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¡£
phpMyAdminµÄº£ÄÚÊý¾Ýͳ¼ÆÍ¼ÈçÏ£º
Îó²îÆÊÎö
ÔÚ/index.php
ÕâÀïµÄtarget ¿ÉÒÔÖ±½Ó´«ÖµÊäÈë¡£¡£¡£¡£¡£ÎÒÃÇ¿ÉÒÔ´«ÈëÒ»¸öÍâµØÎļþ·¾¶È¥ÈÃÆä°üÀ¨£¬£¬£¬£¬£¬£¬¾Í»áÔì³ÉLFIÎó²î¡£¡£¡£¡£¡£
Ê×ÏÈ£¬£¬£¬£¬£¬£¬ÎÒÃÇÖª×ã4¸öÌõ¼þ£º
2£®²»¿ÉÒÔ/index/ ¿ªÍ·¡£¡£¡£¡£¡£
3£®²»¿ÉÔÚ$target_blacklistÊý×éÄÚ¡£¡£¡£¡£¡£
¸ú×ÙÒ»ÏÂcheckPageValidityº¯Êý
ÔÚ/libraries/classes/Core.php
¸Ãº¯ÊýÄÚ£¬£¬£¬£¬£¬£¬ÓÐÈý´¦·µ»ØtureµÄµØ·½£¬£¬£¬£¬£¬£¬Ö»ÒªÓÐí§ÒâÒ»´¦·µ»Øture¾Í¿ÉÒÔ¡£¡£¡£¡£¡£ÊÓ²ìÕâÈý´¦£¬£¬£¬£¬£¬£¬ÓÐÒ»¸öÅäºÏµã£¬£¬£¬£¬£¬£¬¶¼ÊÇÐèÒª$pageÔÚ$whitelistÊý×éÖÐÄڲŻ᷵»Øtrue¡£¡£¡£¡£¡£
ÎÒÃÇÏÈ¿´µÚÒ»¸ö·µ»ØtrueµÄµØ·½¡£¡£¡£¡£¡£

ÕâÀïµÄ$pageÔÚin_array֮ǰûÓоÓÉÈκεÄÐÞÊΣ¬£¬£¬£¬£¬£¬Ö±½Ó¾ÍÓë$whitelist×÷½ÏÁ¿¡£¡£¡£¡£¡£Ã»Óв½·¥Èƹý£¬£¬£¬£¬£¬£¬´«ÈëµÄtargetÖµÖ»ÄÜΪ°×Ãûµ¥ÀïµÄÎļþÃû²ÅÐС£¡£¡£¡£¡£ºÜÏÔ×Å£¬£¬£¬£¬£¬£¬µÚÒ»¸ö²¢²»¿ÉʹÓᣡ£¡£¡£¡£
ÔÙÀ´¿´µÚ¶þ¸ö

ÏÈÏÈÈÝÏÂÕâЩº¯ÊýµÄ×÷Óãº
mb_strpos()º¯ÊýµÄÒâ˼ÊDzéÕÒ×Ö·û´®ÔÚÁíÒ»¸ö×Ö·û´®ÖÐÊ״ηºÆðµÄλÖᣡ£¡£¡£¡£
mb_substr()º¯ÊýµÄÒâ˼ÊÇ£º
´Ó$str×Ö·û´®ÖУ¬£¬£¬£¬£¬£¬ÌáÈ¡´Ó$startλÖÃ×îÏÈ£¬£¬£¬£¬£¬£¬³¤¶ÈΪ$lengthµÄ×Ö·û´®¡£¡£¡£¡£¡£
¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬£¬µÚ¶þ¸ö¿ÉÒÔ·µ»Øture£¬£¬£¬£¬£¬£¬ÎÒÃÇʹÓÃdb_sql.php?/../../ÃûÌþͿÉÒÔµÖ´ïÄ¿µÄ£¬£¬£¬£¬£¬£¬Èƹý°×Ãûµ¥ÏÞÖÆ¡£¡£¡£¡£¡£ÄÇÊDz»ÊÇÕâÑù¾Í¿ÉÒÔÔì³ÉÎó²îÁËÄØ£¿£¿
¼ÙÉèÎÒÃÇÓÃdb_sql.php?/../../../aaa.txtÀ´Èƹý°×Ãûµ¥ÏÞÖÆ¾ÙÐаüÀ¨Îļþ¡£¡£¡£¡£¡£

ÄÇÕâÀï¾ÍÊÇ include ¡®db_sql.php?/../../../aaa.txt¡¯¡£¡£¡£¡£¡£
ÕâÖÖÃûÌò¢²»¿É¿ç·¾¶°üÀ¨£¬£¬£¬£¬£¬£¬ÓÉÓÚphp³ÌÐò°Ñ£¿£¿ºÅºóÃæµÄ¹¤¾ßµ±³ÉÊÇ´«Èëdb_sql.phpÎļþµÄ²ÎÊý¡£¡£¡£¡£¡£
ÔÙÀ´¿´µÚÈý¸ö£º

µÚÈý¸öºÍµÚ¶þ¸ö±ÈÕÕ¶à³öÁ˸öurldecode()º¯Êý¡£¡£¡£¡£¡£
¶øÎÊÌâǡǡ³öÔÚÁËÕâ¸öurldecode()º¯Êý¡£¡£¡£¡£¡£
Ôµ¹ÊÔÓÉÊÇ£º
%253f ´«Èëʱ£¬£¬£¬£¬£¬£¬Ê×ÏȻᱻ×Ô¶¯½âÂëÒ»´Î£¬£¬£¬£¬£¬£¬Äð³É%3f¡£¡£¡£¡£¡£È»ºóurldecode()ÔÙ½âÂëÒ»´Î£¬£¬£¬£¬£¬£¬¾ÍÄð³ÉÁË ?¡£¡£¡£¡£¡£ ÀÖ³ÉÈÆ¹ýÁ˰×Ãûµ¥ÏÞÖÆ¡£¡£¡£¡£¡£
ÕâÖÖÇéÐÎÏÂincludeµÄ°üÀ¨ÇéÐξÍÊÇÕâÑùµÄ£¬£¬£¬£¬£¬£¬Ò²¾Í¿ÉÒÔí§Òâ°üÀ¨ÍâµØÎļþÁË¡£¡£¡£¡£¡£
Îó²îʹÓÃ
ÍêÕûµÄexp£º
tips£º
1¡¢%3f ½«±»½âÂë²¢³ÉΪ?¡£¡£¡£¡£¡£
2¡¢Core::checkPageValidity°þÀëËùÓÐÄÚÈÝ?²¢sql.phpÔÚ°×Ãûµ¥ÄÚÕÒµ½£º¼ì²é±»Èƹý£¡3¡¢index.phpÔËÐÐinclude 'sql.php?/../../etc/passwd'£¬£¬£¬£¬£¬£¬PHPµÄħÊõÀ´×ª»»Â·¾¶ ../etc/passwd£¬£¬£¬£¬£¬£¬¶ø²»¼ì²éĿ¼ÊÇ·ñsql.php?±£´æ¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬Ëü°üÀ¨../etc/passwdÀֳɡ£¡£¡£¡£¡£
ҪдÕâ¸öÎó²î£¬£¬£¬£¬£¬£¬¿ÉÒÔö¾ÙÎļþ·¾¶£¬£¬£¬£¬£¬£¬È磺
/etc/passwd
../../etc/passwd../windows/win.ini
../../windows/win.ini
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬Ðû²¼ÁË×îа汾4.8.2£¬£¬£¬£¬£¬£¬¿É´Ó¹ÙÍøÏÂÔØ×îа汾¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.securityfocus.com/bid/104532
https://nvd.nist.gov/vuln/detail/CVE-2018-12613


¾©¹«Íø°²±¸11010802024551ºÅ