phpMyAdminÔ¶³ÌÖ´ÐдúÂëÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2018-07-03Îó²î±àºÅºÍ¼¶±ð
Ó°Ïì¹æÄ£
ÊÜÓ°ÏìµÄϵͳ°æ±¾£º
phpMyAdmin 4.8.1
Îó²î¸ÅÊö
phpMyAdmin ÊÇÒ»¸öÒÔPHPΪ»ù´¡£¬£¬£¬£¬£¬£¬ÒÔWeb-Base·½·¨¼Ü¹¹ÔÚÍøÕ¾Ö÷»úÉϵÄMySQLµÄÊý¾Ý¿âÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬ÈÃÖÎÀíÕß¿ÉÓÃWeb½Ó¿ÚÖÎÀíMySQLÊý¾Ý¿â¡£¡£¡£¡£¡£¡£
ÔÚphpMyAdmin 4.8.x°æ±¾ÖУ¬£¬£¬£¬£¬£¬³ÌÐòûÓÐÑÏ¿á¿ØÖÆÓû§µÄÊäÈ룬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃË«ÖØ±àÂëÈÆ¹ý³ÌÐòµÄ°×Ãûµ¥ÏÞÖÆ£¬£¬£¬£¬£¬£¬Ôì³ÉÎļþ°üÀ¨Îó²î¡£¡£¡£¡£¡£¡£
´ËÎó²îʹ¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâPHP´úÂë¡£¡£¡£¡£¡£¡£
phpMyAdminµÄº£ÄÚÊý¾Ýͳ¼ÆÍ¼ÈçÏ£º
Îó²îÆÊÎö
ÔÚ/index.php
ÕâÀïµÄtarget ¿ÉÒÔÖ±½Ó´«ÖµÊäÈë¡£¡£¡£¡£¡£¡£ÎÒÃÇ¿ÉÒÔ´«ÈëÒ»¸öÍâµØÎļþ·¾¶È¥ÈÃÆä°üÀ¨£¬£¬£¬£¬£¬£¬¾Í»áÔì³ÉLFIÎó²î¡£¡£¡£¡£¡£¡£
Ê×ÏÈ£¬£¬£¬£¬£¬£¬ÎÒÃÇÖª×ã4¸öÌõ¼þ£º
2£®²»¿ÉÒÔ/index/ ¿ªÍ·¡£¡£¡£¡£¡£¡£
3£®²»¿ÉÔÚ$target_blacklistÊý×éÄÚ¡£¡£¡£¡£¡£¡£
¸ú×ÙÒ»ÏÂcheckPageValidityº¯Êý
ÔÚ/libraries/classes/Core.php
¸Ãº¯ÊýÄÚ£¬£¬£¬£¬£¬£¬ÓÐÈý´¦·µ»ØtureµÄµØ·½£¬£¬£¬£¬£¬£¬Ö»ÒªÓÐí§ÒâÒ»´¦·µ»Øture¾Í¿ÉÒÔ¡£¡£¡£¡£¡£¡£ÊÓ²ìÕâÈý´¦£¬£¬£¬£¬£¬£¬ÓÐÒ»¸öÅäºÏµã£¬£¬£¬£¬£¬£¬¶¼ÊÇÐèÒª$pageÔÚ$whitelistÊý×éÖÐÄڲŻ᷵»Øtrue¡£¡£¡£¡£¡£¡£
ÎÒÃÇÏÈ¿´µÚÒ»¸ö·µ»ØtrueµÄµØ·½¡£¡£¡£¡£¡£¡£

ÕâÀïµÄ$pageÔÚin_array֮ǰûÓоÓÉÈκεÄÐÞÊΣ¬£¬£¬£¬£¬£¬Ö±½Ó¾ÍÓë$whitelist×÷½ÏÁ¿¡£¡£¡£¡£¡£¡£Ã»Óв½·¥Èƹý£¬£¬£¬£¬£¬£¬´«ÈëµÄtargetÖµÖ»ÄÜΪ°×Ãûµ¥ÀïµÄÎļþÃû²ÅÐС£¡£¡£¡£¡£¡£ºÜÏÔ×Å£¬£¬£¬£¬£¬£¬µÚÒ»¸ö²¢²»¿ÉʹÓᣡ£¡£¡£¡£¡£
ÔÙÀ´¿´µÚ¶þ¸ö

ÏÈÏÈÈÝÏÂÕâЩº¯ÊýµÄ×÷Óãº
mb_strpos()º¯ÊýµÄÒâ˼ÊDzéÕÒ×Ö·û´®ÔÚÁíÒ»¸ö×Ö·û´®ÖÐÊ״ηºÆðµÄλÖᣡ£¡£¡£¡£¡£
mb_substr()º¯ÊýµÄÒâ˼ÊÇ£º
´Ó$str×Ö·û´®ÖУ¬£¬£¬£¬£¬£¬ÌáÈ¡´Ó$startλÖÃ×îÏÈ£¬£¬£¬£¬£¬£¬³¤¶ÈΪ$lengthµÄ×Ö·û´®¡£¡£¡£¡£¡£¡£
¿ÉÒÔ¿´³ö£¬£¬£¬£¬£¬£¬µÚ¶þ¸ö¿ÉÒÔ·µ»Øture£¬£¬£¬£¬£¬£¬ÎÒÃÇʹÓÃdb_sql.php?/../../ÃûÌþͿÉÒÔµÖ´ïÄ¿µÄ£¬£¬£¬£¬£¬£¬Èƹý°×Ãûµ¥ÏÞÖÆ¡£¡£¡£¡£¡£¡£ÄÇÊDz»ÊÇÕâÑù¾Í¿ÉÒÔÔì³ÉÎó²îÁËÄØ£¿£¿£¿£¿£¿£¿
¼ÙÉèÎÒÃÇÓÃdb_sql.php?/../../../aaa.txtÀ´Èƹý°×Ãûµ¥ÏÞÖÆ¾ÙÐаüÀ¨Îļþ¡£¡£¡£¡£¡£¡£

ÄÇÕâÀï¾ÍÊÇ include ¡®db_sql.php?/../../../aaa.txt¡¯¡£¡£¡£¡£¡£¡£
ÕâÖÖÃûÌò¢²»¿É¿ç·¾¶°üÀ¨£¬£¬£¬£¬£¬£¬ÓÉÓÚphp³ÌÐò°Ñ£¿£¿£¿£¿£¿£¿ºÅºóÃæµÄ¹¤¾ßµ±³ÉÊÇ´«Èëdb_sql.phpÎļþµÄ²ÎÊý¡£¡£¡£¡£¡£¡£
ÔÙÀ´¿´µÚÈý¸ö£º

µÚÈý¸öºÍµÚ¶þ¸ö±ÈÕÕ¶à³öÁ˸öurldecode()º¯Êý¡£¡£¡£¡£¡£¡£
¶øÎÊÌâǡǡ³öÔÚÁËÕâ¸öurldecode()º¯Êý¡£¡£¡£¡£¡£¡£
Ôµ¹ÊÔÓÉÊÇ£º
%253f ´«Èëʱ£¬£¬£¬£¬£¬£¬Ê×ÏȻᱻ×Ô¶¯½âÂëÒ»´Î£¬£¬£¬£¬£¬£¬Äð³É%3f¡£¡£¡£¡£¡£¡£È»ºóurldecode()ÔÙ½âÂëÒ»´Î£¬£¬£¬£¬£¬£¬¾ÍÄð³ÉÁË ?¡£¡£¡£¡£¡£¡£ ÀÖ³ÉÈÆ¹ýÁ˰×Ãûµ¥ÏÞÖÆ¡£¡£¡£¡£¡£¡£
ÕâÖÖÇéÐÎÏÂincludeµÄ°üÀ¨ÇéÐξÍÊÇÕâÑùµÄ£¬£¬£¬£¬£¬£¬Ò²¾Í¿ÉÒÔí§Òâ°üÀ¨ÍâµØÎļþÁË¡£¡£¡£¡£¡£¡£
Îó²îʹÓÃ
ÍêÕûµÄexp£º
tips£º
1¡¢%3f ½«±»½âÂë²¢³ÉΪ?¡£¡£¡£¡£¡£¡£
2¡¢Core::checkPageValidity°þÀëËùÓÐÄÚÈÝ?²¢sql.phpÔÚ°×Ãûµ¥ÄÚÕÒµ½£º¼ì²é±»Èƹý£¡3¡¢index.phpÔËÐÐinclude 'sql.php?/../../etc/passwd'£¬£¬£¬£¬£¬£¬PHPµÄħÊõÀ´×ª»»Â·¾¶ ../etc/passwd£¬£¬£¬£¬£¬£¬¶ø²»¼ì²éĿ¼ÊÇ·ñsql.php?±£´æ¡£¡£¡£¡£¡£¡£×îºó£¬£¬£¬£¬£¬£¬Ëü°üÀ¨../etc/passwdÀֳɡ£¡£¡£¡£¡£¡£
ҪдÕâ¸öÎó²î£¬£¬£¬£¬£¬£¬¿ÉÒÔö¾ÙÎļþ·¾¶£¬£¬£¬£¬£¬£¬È磺
/etc/passwd
../../etc/passwd../windows/win.ini
../../windows/win.ini
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬Ðû²¼ÁË×îа汾4.8.2£¬£¬£¬£¬£¬£¬¿É´Ó¹ÙÍøÏÂÔØ×îа汾¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.securityfocus.com/bid/104532
https://nvd.nist.gov/vuln/detail/CVE-2018-12613