Korean GHBoard Multiple Vulnerabilities by Xcross87 Oct 23 2007 06:01PM
pete houston 17187 gmail com
Software : Korean GHBoard

Site : http://www.ghlab.com/

Found by : Xcross87

1. File Upload Vulnerability

Xploit :


2. FlashUpload component File Upload and File Download Vulnerability

Upload Xploit :


Not allow upload php,jsp,html

But attacker can download source and remove javascript code which check for file type and upload easily.

Uploaded file is located in :


Download Xploit :

You can download any file from server :


Sample :


3. FCK Inclusion :

All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server.

=== Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===

