΢ÐÅÖ§¸¶SDK XXE·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-07-03

·ì϶±àºÅºÍ¼¶±ð


ÎÞ  ¸ßΣ


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º


JAVA SDK£¬£¬£¬£¬£¬ £¬WxPayAPI_JAVA_v3


·ì϶¸ÅÊö

΢ÐÅÔÚJAVA°æ±¾µÄSDKÖÐÌṩcallback»Øµ÷Ö°ÄÜ£¬£¬£¬£¬£¬ £¬ÓÃÀ´Ô®ÊÖÉ̼ҽӹÜÒì²½¸¶¿îÁ˾֣¬£¬£¬£¬£¬ £¬¸Ã½Ó¿Ú½ÓÊÜXMLÌåʽµÄÊý¾Ý£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâµÄ»Øµ÷Êý¾Ý£¨XMLÌåʽ£©À´ÇÔÈ¡É̼ҷþÎñÆ÷ÉϵÄÈκÎÐÅÏ¢¡£¡£ ¡£¡£¡£¡£Ò»µ©¹¥»÷Õß»ñµÃÁ˹ؼüÖ§¸¶µÄ°²È«ÃÜÔ¿£¨md5-keyºÍÉ̼ÒÐÅÏ¢£©£¬£¬£¬£¬£¬ £¬½«Äܹ»Ö±½ÓʵÏÖ0ÔªÖ§¸¶²É°ìÈκÎÉÌÆ·¡£¡£ ¡£¡£¡£¡£µ±XMLÔÊÐíÒýÓÃ±í²¿ÊµÌåʱ£¬£¬£¬£¬£¬ £¬ºÚ¿ÍÄܹ»Í¨¹ý»ú¹Ø¶ñÒâXMLʵÌåÎļþ£¬£¬£¬£¬£¬ £¬ÊµÏÖÔ¶³Ì¶ÁÈ¡ËÁÒâϵͳÎļþ¡¢Ô¶³ÌÖ´ÐÐϵͳºÅÁîµÈһϵÁÐΣÏÕ²Ù×÷£¬£¬£¬£¬£¬ £¬ÑϳÁ·çÏÕÉ̼ҷþÎñÆ÷µÄϵͳ°²È«¡£¡£ ¡£¡£¡£¡£


XXE (XML External Entity Injection) ·ì϶²úÉúÔÚÀûÓ÷¨Ê½½âÎö XML ÊäÈëʱ£¬£¬£¬£¬£¬ £¬Ã»Óв»ÈÝ±í²¿ÊµÌåµÄ¼ÓÔØ¡£¡£ ¡£¡£¡£¡£ÊÇÒ»ÖÖÕë¶ÔʹÓÃXML½»»¥µÄWebÀûÓ÷¨Ê½µÄ¹¥»÷²½Öè¡£¡£ ¡£¡£¡£¡£


Ŀǰ£¬£¬£¬£¬£¬ £¬Î¢ÐŹٷ½ÉÐδ¶ÔSDK½øÐн¨¸´£¬£¬£¬£¬£¬ £¬µ«·ì϶ÀûÓÃÐÅÏ¢ÒÔ¼°¹¥»÷·½Ê½Òѱ»¹«¿ª£¬£¬£¬£¬£¬ £¬Ó°ÏìÁìÓò¾Þ´ó£¨ÒѾ­Åû¶³öµÄÓÐİİ¡¢vivoÈ·ÈÏ´æÔڸ÷ì϶£©£¬£¬£¬£¬£¬ £¬½¨ÒéÓõ½Î¢ÐÅÖ§¸¶JAVA SDKµÄÆóÒµÁ¢¿Ì·¢Õ¹×Բ鲢¹Ø×¢Î¢ÐŹٷ½°²È«¹«¸æ¡£¡£ ¡£¡£¡£¡£


2018Äê7ÔÂ2ºÅ£¬£¬£¬£¬£¬ £¬¸Ã·ì϶ÔÚ¹ú±í·ì϶ÅûÂ¶ÍøÕ¾³õ´Î°ä²¼£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾µØÑéÖ¤½ØÍ¼£º


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


½¨¸´½¨Òé


ÆÚ´ý΢ÐŹٷ½Éý¼¶¹æ»®¡£¡£ ¡£¡£¡£¡£


Óû§¿ÉʹÓÿª·¢Ëµ»°ÌṩµÄ½ûÓÃ±í²¿ÊµÌåµÄ²½Öè¡£¡£ ¡£¡£¡£¡£java½ûÓÃ±í²¿ÊµÌåµÄ´úÂëÈçÏ£º


DocumentBuilderFactory dbf =DocumentBuilderFactory.newInstance();
dbf.setExpandEntityReferences(false);


²Î¿¼Á´½Ó

http://seclists.org/fulldisclosure/2018/Jul/3¡£¡£ ¡£¡£¡£¡£