Ajax File Manager File Upload defect and repair

Source: Internet
Author: User

 

Title: Ajax File Manager File Upload Vulnerability

Author: X-Cisadane www.2cto.com

: Http://www.phpletter.com

Affected Versions: All

Defect: File Upload

Test Platform: Google Chrome 14.0.835 (Windows)

Labels -------------------------------------------------------------------------------------------------------------------------:

 

Description:

Ajax File Manager is a Plug-ins which you can add on FCKEditor/TinyMCE on the CMS as a File Management, for example: Uploading File (Text, Image, dll ), create A New Folder, Copy, Cut, Delete File or Directory. file that can be uploaded is depend on The Website Configuration. some Ajax File Manager configured without an authentification (No Login Form), So we can view directories and files on Ajax File Manager or upload/delete/cut/copy/paste/create new folder.

 

How?

[1] Open Google Search Engine, Type the dork: inurl:/plugins/ajaxfilemanager/

[2] For Example you got:

Http://www.bkjia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/jscripts/edit_area/reg_syntax/

 

Change the URL on your Browser into: http://lovegracia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php

 

OR

 

Http://www.ziaislamic.com/BOOK-CMS/interfaces/fckeditor/editor/plugins/ajaxfilemanager/session/

 

Change the URL on your Browser into: http://www.ziaislamic.com/BOOK-CMS/interfaces/fckeditor/editor/plugins/ajaxfilemanager/ajaxfilemanager.php

 

[3] If the Ajax File Manager don't have a Login Form, so we can head up into File Manager directly and uploading file or whatever you can do.

Like this:

Http://www.ziaislamic.com/BOOK-CMS/interfaces/fckeditor/editor/plugins/ajaxfilemanager/ajaxfilemanager.php

Http://www.thebradshawscornershop.co.uk/scripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php

Http://lovegracia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php

Http://www.bkjia.com/brantas_portal/assets/tinymce/plugins/ajaxfilemanager. php

Http://www.apmsa.org.za/admin/scripts/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php

 

Results:

Http://www.ziaislamic.com/BOOK-CMS/interfaces/uploaded/dwi/bekdort.txt

Http://www.thebradshawscornershop.co.uk/images/dwi/bekdort.txt

Http://lovegracia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/uploaded/dwi/bekdort.txt

Http://www.bkjia.com/brantas_portal/uploaded_docimage/diffusion/bekdort.txt

Http://www.apmsa.org.za/admin/scripts/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/uploaded/dwi/bekdort.txt

 

P.S: Default Password Ajax File Manager

Username: ajax

Password: 123456

 

-= Regards =-

Spread a. k. a X-Cisadane

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.