This article is a mirror article of machine translation, please click here to jump to the original article.

View: 14246|Reply: 4

[Safe Communication] Fckeditor hacked a certain website

[Copy link]
Posted on 4/13/2015 11:01:34 AM | | | |
A vulnerability in the Fckeditor editor has been detected on a certain site. OK, let's go straight to the tool.



You can see directories, create folders, and upload files.

The server is IIS6, upload a sentence, xx.asp; 1.gif, but what I got after uploading is like this.



After the visit, I was intercepted by the security dog, thinking that I had been killed, so I found a safety dog and uploaded it, and it was still the same. After careful analysis, it was a problem with the incoming parameters, so a xx.asp.jpg horse was uploaded, and it was successfully uploaded.





The kitchen knife is directly connected and taken down.




Previous:Windows 7 and Ubuntu dual system installation
Next:win32, win64 kill-free power lifting tool
Posted on 4/13/2015 9:34:10 PM |
It is quite convenient to include a dog
Posted on 4/13/2015 9:35:28 PM |
1.asp; Wheel, wheelThe .jpg is a
 Landlord| Posted on 4/13/2015 10:34:04 PM |
whoami posted on 2015-4-13 21:35
1.asp; The yoke is the same as the yoke ...

What are you going to do?"
Posted on 4/14/2015 7:59:53 PM |
I can't understand
Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com