FCKeditor: Remote file upload exploit.





Dork: intitle:"FCKeditor - Uploaders Tests"


Exploit:http://website.domain/fckeditor/editor/filemanager/connectors/uploadtest.html


By searching this dork you will get many websites, goto to the above mentioned URL and you will get the FCKeditor there. Change the file uploader to PHP then select your .txt deface and click on send it to the server. If the file is uploaded sucessfully you will get a alert saying "File Uploaded with no errors" .
See you deface here:



http://www.website.domain/userfiles/yourfilehere
http://www.website.domain/path/userfiles/yourfilehere


Note: Some websites even allow to upload .html and .jpg files also.





FCKeditor: Remote file upload exploit. FCKeditor: Remote file upload exploit. Reviewed by Almas Malik on 00:34 Rating: 5

1 comment:

  1. The perfect!These articles written too great,they rich contents and data accurately.they are help to me.I expect to see your new share.


    --------------------------------------------------------------------------------------------------
    Column Wedding Dresses|Flower Girl Dresses|Empire Wedding Dresses|New Style Wedding Dresses

    ReplyDelete

Powered by Blogger.