华夏ERP_v2.3.1最新版SQL注入与RCE漏洞审计

需积分: 0 12 下载量 117 浏览量 更新于2024-08-05 收藏 1.4MB PDF 举报
华夏ERP_v2.3.1最新版SQL与RCE的审计过程 华夏ERP_v2.3.1最新版SQL与RCE的审计过程是指对华夏ERP_v2.3.1版本的审计过程,主要关注SQL注入漏洞和远程命令执行(RCE)的检测。该过程包括代码路径、软件版本、源码审计、数据流跟踪、权限检查、数据过滤、漏洞模式等多个方面。 **代码路径** 代码路径是指华夏ERP_v2.3.1的代码仓库地址,位于https://gitee.com/jishenghua/JSH_ERP。该仓库包含了华夏ERP_v2.3.1的所有源代码。 **软件版本** 软件版本是指华夏ERP_v2.3.1的版本号,该版本存在SQL注入漏洞和RCE漏洞。 **源码审计** 源码审计是指对华夏ERP_v2.3.1的源代码进行安全检测,以查找潜在的漏洞。该过程从外部输入点开始,跟踪数据流,判断数据处理过程中是否存在一些常见的漏洞,例如SQL注入漏洞。 **数据流跟踪** 数据流跟踪是指跟踪数据从外部输入点到系统内部的流程,以判断数据处理过程中是否存在一些常见的漏洞。该过程需要关注权限检查、数据过滤、以及平时积累的漏洞模式,例如XXE、SQL注入等。 **Filter** Filter是指华夏ERP_v2.3.1中的一个Filter组件,名为LogCostFilter。该Filter组件负责检查用户是否登录,如果没有登录就会让用户重定向到login.html。 **认证绕过** 认证绕过是指攻击者可以绕过华夏ERP_v2.3.1的认证机制,以获取未经授权的访问权限。该漏洞可能存在于LogCostFilter组件中,攻击者可以通过绕过认证来执行恶意代码。 **漏洞模式** 漏洞模式是指华夏ERP_v2.3.1中的常见漏洞模式,例如SQL注入漏洞、RCE漏洞等。这些漏洞可能存在于系统的各个组件中,例如Filter、Controller等。 **系统配置文件** 系统配置文件是指华夏ERP_v2.3.1的配置文件,例如web.xml。该文件包含了系统的配置信息,可以用于查找系统的入口点。 **入口点** 入口点是指华夏ERP_v2.3.1的外部数据入口点,例如Filter、Controller等。这些入口点可能存在漏洞,攻击者可以通过这些漏洞来执行恶意代码。 华夏ERP_v2.3.1最新版SQL与RCE的审计过程是指对华夏ERP_v2.3.1版本的安全检测,以查找潜在的漏洞。该过程需要关注代码路径、软件版本、源码审计、数据流跟踪、权限检查、数据过滤、漏洞模式等多个方面,以确保系统的安全性。
2023-01-08 上传
Manage( 管理员表) "列名 "列的数据类型 "是否能为"默认值 "说明 " " " "空 " " " "Manger_Id "int "0 " "主键,自增 " "Manger_Name "Nvarchar(10) "0 " "管理员登录 " " " " " "名 " "Manger_Pwd "Nvarchar(32) "0 " "管理员MD5加" " " " " "密后的密码 " "Manger_RealName "Nvarchar(5) "0 " "管理员的真 " " " " " "实姓名,这 " " " " " "里考虑到复 " " " " " "姓 " "Manger_Address "Nvarchar(50) "0 " "管理员的住 " " " " " "址 " "Manger_Mobile "Nvarchar(11) "0 " "管理员的手 " " " " " "机号 " "Manger_Tel "Nvarchar(11) "0 " "管理员的办 " " " " " "公电话(带 " " " " " "区号) " "Manger_Gender "bit "1 "0 "管理员的性 " " " " " "别0为男性," " " " " "1为女性 " "Manger_IdNum "Nvarchar(18) "0 " "管理员的身 " " " " " "份证号 " "Manger_AddTime "Date "0 " "管理员添加 " " " " " "的时间 " "Manger_UpdateTime "Date "1 "和添加时 "管理员修改 " " " " "间相同 "的时间 " "Manger_TypeGroupId "Nvarchar(3) "0 " "管理员权限 " " " " " "组 " "Manger_TypeId "Nvarchar(50) "0 " "管理员所有 " " " " " "的权限用"," " " " " ""分割 " "Manger_IsLock "bit "0 " "管理员是否 " " " " " "禁用 " "Manger_MsgUnReadId "Nvarchar(max) "1 "您的消息 "管理员未读 " " " " "已经读完 "消息id用"," " " " "了 ""分割 " "Manger_CustomerUnDo"Nvarchar(max) "1 "暂时还没 "管理员尚未 " " " " "有 "完成的安排 " " " " " "客户的任务 " "Manger_ShouldData "Int "1 "0 "管理员应该 " " " " " "完成的任务 " " " " " "数量 " "Manger_HasDoneData "Int "1 "0 "管理员已经 " " " " " "完成的任务 " " " " " "数量 " Message表(网站公告表) "列名 "数据类型 "是否能为 "默认值 "说明 " " " "空 " " " "Msg_Id "Int "0 " "公告ID,主键" " " " " ",自增 " "Msg_FromMangerId "Int "0 " "发送公告的 " " " " " "管理员Id " "Msg_ToGroupId "Int "0 " "管理员发送 " " " " " "到的用户组I" " " " " "d " "Msg_Title "Nvarchar(25) "0 " "公告的标题," " " " " "最长25个中 " " " " " "文字符 " "Msg_Summary "Nvarchar(255) "1 "文件内容 "公告的摘要 " " " " "的前255个"部分,最长 " " " " "字 "为255个中文" " " " " "字符 " "Msg_Coutent "Nvarchar(max) "0 " "公告的主题 " " " " " "部分 " "Msg_IsTop "bit "1 "0 "公告是否置 " " " " " "顶 " "Msg_IsImportent "Bit "1 "0 "公告是否为 " " " " " "重要类型 " "Msg_IsEmergent "Bit "1 "0 "公告是否为 " " " " " "紧急类型 " Customer表(客户表) "列名 "数据类型 "是否可 "默认值 "说明 " " " "为空 " " " "Customer_Id "Int "0 " "客户的id " "Customer_MangerID "Int "0 " "客户所属的" " " " " "管理员的id" "Customer_CompanyId "Int "0 " "客户所属公" " " " " "司id