phpMyAdminÔ¶³ÌÖ´ÐдúÂëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-03Îó²î±àºÅºÍ¼¶±ð
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄϵͳ°æ±¾£º
phpMyAdmin 4.8.1
Îó²î¸ÅÊö
phpMyAdmin ÊÇÒ»¸öÒÔPHPΪ»ù´¡£¡£¡£¡£¡£¬£¬£¬£¬£¬ÒÔWeb-Base·½·¨¼Ü¹¹ÔÚÍøÕ¾Ö÷»úÉϵÄMySQLµÄÊý¾Ý¿âÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬ÈÃÖÎÀíÕß¿ÉÓÃWeb½Ó¿ÚÖÎÀíMySQLÊý¾Ý¿â¡£¡£¡£¡£¡£
ÔÚphpMyAdmin 4.8.x°æ±¾ÖУ¬£¬£¬£¬£¬³ÌÐòûÓÐÑÏ¿á¿ØÖÆÓû§µÄÊäÈ룬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃË«ÖØ±àÂëÈÆ¹ý³ÌÐòµÄ°×Ãûµ¥ÏÞÖÆ£¬£¬£¬£¬£¬Ôì³ÉÎļþ°üÀ¨Îó²î¡£¡£¡£¡£¡£
´ËÎó²îʹ¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¡£
phpMyAdminµÄº£ÄÚÊý¾Ýͳ¼ÆÍ¼ÈçÏ£º
Îó²îÆÊÎö
ÔÚ/index.php
ÕâÀïµÄtarget ¿ÉÒÔÖ±½Ó´«ÖµÊäÈë¡£¡£¡£¡£¡£ÎÒÃÇ¿ÉÒÔ´«ÈëÒ»¸öÍâµØÎļþ·¾¶È¥ÈÃÆä°üÀ¨£¬£¬£¬£¬£¬¾Í»áÔì³ÉLFIÎó²î¡£¡£¡£¡£¡£
Ê×ÏÈ£¬£¬£¬£¬£¬ÎÒÃÇÖª×ã4¸öÌõ¼þ£º
2£®²»¿ÉÒÔ/index/ ¿ªÍ·¡£¡£¡£¡£¡£
3£®²»¿ÉÔÚ$target_blacklistÊý×éÄÚ¡£¡£¡£¡£¡£
¸ú×ÙÒ»ÏÂcheckPageValidityº¯Êý
ÔÚ/libraries/classes/Core.php
¸Ãº¯ÊýÄÚ£¬£¬£¬£¬£¬ÓÐÈý´¦·µ»ØtureµÄµØ·½£¬£¬£¬£¬£¬Ö»ÒªÓÐí§ÒâÒ»´¦·µ»Øture¾Í¿ÉÒÔ¡£¡£¡£¡£¡£ÊÓ²ìÕâÈý´¦£¬£¬£¬£¬£¬ÓÐÒ»¸öÅäºÏµã£¬£¬£¬£¬£¬¶¼ÊÇÐèÒª$pageÔÚ$whitelistÊý×éÖÐÄڲŻ᷵»Øtrue¡£¡£¡£¡£¡£
ÎÒÃÇÏÈ¿´µÚÒ»¸ö·µ»ØtrueµÄµØ·½¡£¡£¡£¡£¡£

ÕâÀïµÄ$pageÔÚin_array֮ǰûÓоÓÉÈκεÄÐÞÊΣ¬£¬£¬£¬£¬Ö±½Ó¾ÍÓë$whitelist×÷½ÏÁ¿¡£¡£¡£¡£¡£Ã»Óв½·¥Èƹý£¬£¬£¬£¬£¬´«ÈëµÄtargetÖµÖ»ÄÜΪ°×Ãûµ¥ÀïµÄÎļþÃû²ÅÐС£¡£¡£¡£¡£ºÜÏÔ×Å£¬£¬£¬£¬£¬µÚÒ»¸ö²¢²»¿ÉʹÓᣡ£¡£¡£¡£
ÔÙÀ´¿´µÚ¶þ¸ö

ÏÈÏÈÈÝÏÂÕâЩº¯ÊýµÄ×÷Óãº
mb_strpos()º¯ÊýµÄÒâ˼ÊDzéÕÒ×Ö·û´®ÔÚÁíÒ»¸ö×Ö·û´®ÖÐÊ״ηºÆðµÄλÖᣡ£¡£¡£¡£
mb_substr()º¯ÊýµÄÒâ˼ÊÇ£º
´Ó$str×Ö·û´®ÖУ¬£¬£¬£¬£¬ÌáÈ¡´Ó$startλÖÃ×îÏÈ£¬£¬£¬£¬£¬³¤¶ÈΪ$lengthµÄ×Ö·û´®¡£¡£¡£¡£¡£
¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬µÚ¶þ¸ö¿ÉÒÔ·µ»Øture£¬£¬£¬£¬£¬ÎÒÃÇʹÓÃdb_sql.php?/../../ÃûÌþͿÉÒÔµÖ´ïÄ¿µÄ£¬£¬£¬£¬£¬Èƹý°×Ãûµ¥ÏÞÖÆ¡£¡£¡£¡£¡£ÄÇÊDz»ÊÇÕâÑù¾Í¿ÉÒÔÔì³ÉÎó²îÁËÄØ£¿£¿£¿£¿£¿£¿
¼ÙÉèÎÒÃÇÓÃdb_sql.php?/../../../aaa.txtÀ´Èƹý°×Ãûµ¥ÏÞÖÆ¾ÙÐаüÀ¨Îļþ¡£¡£¡£¡£¡£

ÄÇÕâÀï¾ÍÊÇ include ¡®db_sql.php?/../../../aaa.txt¡¯¡£¡£¡£¡£¡£
ÕâÖÖÃûÌò¢²»¿É¿ç·¾¶°üÀ¨£¬£¬£¬£¬£¬ÓÉÓÚphp³ÌÐò°Ñ£¿£¿£¿£¿£¿£¿ºÅºóÃæµÄ¹¤¾ßµ±³ÉÊÇ´«Èëdb_sql.phpÎļþµÄ²ÎÊý¡£¡£¡£¡£¡£
ÔÙÀ´¿´µÚÈý¸ö£º

µÚÈý¸öºÍµÚ¶þ¸ö±ÈÕÕ¶à³öÁ˸öurldecode()º¯Êý¡£¡£¡£¡£¡£
¶øÎÊÌâǡǡ³öÔÚÁËÕâ¸öurldecode()º¯Êý¡£¡£¡£¡£¡£
Ôµ¹ÊÔÓÉÊÇ£º
%253f ´«Èëʱ£¬£¬£¬£¬£¬Ê×ÏȻᱻ×Ô¶¯½âÂëÒ»´Î£¬£¬£¬£¬£¬Äð³É%3f¡£¡£¡£¡£¡£È»ºóurldecode()ÔÙ½âÂëÒ»´Î£¬£¬£¬£¬£¬¾ÍÄð³ÉÁË ?¡£¡£¡£¡£¡£ ÀÖ³ÉÈÆ¹ýÁ˰×Ãûµ¥ÏÞÖÆ¡£¡£¡£¡£¡£
ÕâÖÖÇéÐÎÏÂincludeµÄ°üÀ¨ÇéÐξÍÊÇÕâÑùµÄ£¬£¬£¬£¬£¬Ò²¾Í¿ÉÒÔí§Òâ°üÀ¨ÍâµØÎļþÁË¡£¡£¡£¡£¡£
Îó²îʹÓÃ
ÍêÕûµÄexp£º
tips£º
1¡¢%3f ½«±»½âÂë²¢³ÉΪ?¡£¡£¡£¡£¡£
2¡¢Core::checkPageValidity°þÀëËùÓÐÄÚÈÝ?²¢sql.phpÔÚ°×Ãûµ¥ÄÚÕÒµ½£º¼ì²é±»Èƹý£¡3¡¢index.phpÔËÐÐinclude 'sql.php?/../../etc/passwd'£¬£¬£¬£¬£¬PHPµÄħÊõÀ´×ª»»Â·¾¶ ../etc/passwd£¬£¬£¬£¬£¬¶ø²»¼ì²éĿ¼ÊÇ·ñsql.php?±£´æ¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬Ëü°üÀ¨../etc/passwdÀֳɡ£¡£¡£¡£¡£
ҪдÕâ¸öÎó²î£¬£¬£¬£¬£¬¿ÉÒÔö¾ÙÎļþ·¾¶£¬£¬£¬£¬£¬È磺
/etc/passwd
../../etc/passwd../windows/win.ini
../../windows/win.ini
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬Ðû²¼ÁË×îа汾4.8.2£¬£¬£¬£¬£¬¿É´Ó¹ÙÍøÏÂÔØ×îа汾¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.securityfocus.com/bid/104532
https://nvd.nist.gov/vuln/detail/CVE-2018-12613


¾©¹«Íø°²±¸11010802024551ºÅ