漏洞概要 关注数(24) 关注此漏洞
缺陷编号:wooyun-2015-089666
漏洞标题:ShopWind网店系统存在fck上传和IIS解析漏洞可批量getshell
相关厂商:ShopWind
漏洞作者: 小骇
提交时间:2015-01-07 15:21
修复时间:2015-04-13 16:58
公开时间:2015-04-13 16:58
漏洞类型:文件上传导致任意代码执行
危害等级:高
自评Rank:11
漏洞状态:未联系到厂商或者厂商积极忽略
漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]
Tags标签: 无
漏洞详情
披露状态:
2015-01-07: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-04-13: 厂商已经主动忽略漏洞,细节向公众公开
简要描述:
ShopWind建站cms存在fck上传和IIS解析漏洞可批量getshell
详细说明:
ShopWind建站cms存在fck上传和IIS解析漏洞可批量getshell。
影响版本ShopWind网店系统 v1.02。
关键字:
漏洞地址:
/fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
上传后文件路径:
/shopwind/images/userfiles/image/...
案例:
http://www.meiliwangluo.com//fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
http://www.pugok.com/shop//fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
http://www.yongminglihui.com/fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
http://www.ygxr.me/shop//fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
http://www.zsrlhf.com/shop//fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
http://www.shunfengu.com//fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp
漏洞证明:
存在fck上传漏洞。
...等等
通过fck上传点和iis解析漏洞,可shell。
以http://www.yongminglihui.com/fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=../../connectors/asp/connector.asp 为例。
修复方案:
,,,,,,fck
版权声明:转载请注明来源 小骇@乌云
漏洞回应
厂商回应:
未能联系到厂商或者厂商积极拒绝