gfr*_*ius 0 sql oracle coldfusion sql-injection
假设ColdFusion 10,0,13,287689和Oracle Database 11g企业版11.2.0.2.0 - 64位生产.
有了这个例子......
<cfquery name="q" datasource="ds">
update someTable set
#form.col#label = <cfqueryparam cfsqltype="cf_sql_varchar" value="#x#">
where id = <cfqueryparam cfsqltype="cf_sql_decimal" value="#id#">
</cfquery>
Run Code Online (Sandbox Code Playgroud)
还假设没有数据验证检查#form.col#,如何利用它?显然,它们可能会导致查询失败并显示无效列,但由于多个语句无法在单个语句中运行,因此我没有看到任何更恶意的行为<cfquery>.所以像这样的东西不起作用......
#form.col#:
id = 1; delete from users; --comment everything else out...
Run Code Online (Sandbox Code Playgroud)
我知道使用SELECT会更容易利用联合来获取您无权查看的数据,但我对这个特定的更新语句很好奇.
虽然SQL注入的传统示例涉及顺序SQL语句,但这只是用于突出显示问题的简单示例 - 如果在任何查询中的任何位置都允许使用不受保护的用户派生文本,则攻击者有可能能够使用它.
在此特定示例中,您的查询是:
update someTable
set #form.col#label = ?
where id = ?`
Run Code Online (Sandbox Code Playgroud)
滥用这很简单 - 在真实col价值前加上类似的东西:
public_column = (SELECT badly_encrypted_password
FROM users WHERE username='admin' ), <orig_value>
Run Code Online (Sandbox Code Playgroud)
结果SQL然后是:
update someTable
set public_column = ( SELECT badly_encrypted_password FROM users WHERE username='admin' )
, <orig_value>label = ?
where id = ?`
Run Code Online (Sandbox Code Playgroud)
当然,将该列的值设置为子查询的结果,然后在另一个区域中单独选择将无意中返回敏感数据.
或者,攻击者可能决定使用此方法简单地删除/删除数据,并且根据Oracle的SQL语法允许的内容,其他事情可能是可能的.