首页 资讯 安全 查看内容

Drupal 7.31 SQL注入漏洞(CVE-2014-3704) EXP测试代码

2014-10-19 16:33 2867 0

摘要: 最近频繁爆发各种0day,真是把大家累坏了。Drupal 7.31 SQL注入漏洞(CVE-2014-3704)就是其中一个,该漏洞利用测试方法“简单粗暴”,受到安全研究者们的青睐。Drupal Sq...
关键词: nbsp array placeholders expandArguments placeholder query replace example 函数 漏洞

最近频繁爆发各种0day,真是把大家累坏了。Drupal 7.31 SQL注入漏洞(CVE-2014-3704)就是其中一个,该漏洞利用测试方法“简单粗暴”,受到安全研究者们的青睐。Drupal Sql注入漏洞原理是酱紫的,Drupal在处理IN语句的时候,要通过expandArguments函数来展开数组。由于expandArguments函数没有对当前数组中key值进行有效的过滤,给攻击者可乘之机。攻击者通过精心构造的SQL语句可以执行任意PHP代码。expandArguments函数如下protected function expandArguments(&$query, &$args) {   $modified = FALSE;     // If the placeholder value to insert is an array, assume that we need   // to expand it out into a comma-delimited set of placeholders.   foreach (array_filter($args, 'is_array') as $key => $data) {     $new_keys = array();     foreach ($data as $i => $value) {       // This assumes that there are no other placeholders that use the same       // name.  For example, if the array placeholder is defined as :example       // and there is already an :example_2 placeholder, this will generate       // a duplicate key.  We do not account for that as the calling code       // is already broken if that happens.       $new_keys[$key . '_' . $i] = $value;     }       // Update the query with the new placeholders.     // preg_replace is necessary to ensure the replacement does not affect     // placeholders that start with the same exact text. For example, if the     // query contains the placeholders :foo and :foobar, and :foo has an     // array of values, using str_replace would affect both placeholders,     // but using the following preg_replace would only affect :foo because     // it is followed by a non-word character.     $query = preg_replace('#' . $key . 'b#', implode(', ', array_keys($new_keys)), $query);       // Update the args array with the new placeholders.     unset($args[$key]);  &nbs
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部