Korean GHBoard Multiple Vulnerabilities by Xcross87

看板Bugtraq作者時間18年前 (2007/10/24 02:34), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
Software : Korean GHBoard Site : http://www.ghlab.com/ Found by : Xcross87 1. File Upload Vulnerability Xploit : victim.com/ghboard/component/upload.jsp 2. FlashUpload component File Upload and File Download Vulnerability Upload Xploit : victim.com/ghboard/component/flashupload/upload.html Not allow upload php,jsp,html But attacker can download source and remove javascript code which check for file type and upload easily. Uploaded file is located in : victim.com/ghboard/component/flashupload/data/upload_filename.xxx Download Xploit : You can download any file from server : victim.com/ghboard/component/flashupload/download.jsp?name=[file_name] Sample : victim.com/ghboard/component/flashupload/download.jsp?name=../config.jsp 3. FCK Inclusion : All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server. === Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===
文章代碼(AID): #177ZxD00 (Bugtraq)