BugTraq
Knowledgeroot (fckeditor) Remote Arbitrary File Upload Exploit May 04 2010 11:59PM
eidelweiss cyberservices com (1 replies)
Re: Knowledgeroot (fckeditor) Remote Arbitrary File Upload Exploit May 05 2010 07:28PM
Frank Habermann (lordlamer lordlamer de)
Hi,

> Restrict access to the
> extension/fckeditor/fckeditor/editor/filemanager/connectors/php/config.p
hp
> script (e.g. via .htaccess)
>
> To Proof This Concept , The Script Remote c0de available here:
>
> http://www.inj3ct0r.com/exploits/12132
I have checked this and your proof of concept does not work for me!

And what should the config.php do? Their is no running code in it. Only a
configuration file.

regards,
Frank

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus