FCK editor explosion absolute path

Source: Internet
Author: User

Haha night cat paper has wood !!!
 
This editor vulnerability has been found in some forums and is not easy to write. I don't know whether you have met this path ..
 
I just discovered that this stuff was not used for private sharing.
 
Such as the problem of explosive path. The principle should be similar to other brute-force paths, which are the absolute paths that make him fail
 
Let's just talk about it ..
 
First, you can find a test.html or local connection. The principle is the same.
 
 

 
Www.2cto.com does not need to create a directory. directly enter an ASP. ASP file under Current Folder to jump to this directory, and an error occurs.
 
Then, you can upload an image path. After the local test is successful
 
 
 
In this way, the path is exposed.

From: Fa ke Forum Author: piaoker
 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.