eWebEditor suffers from a directory traversal vulnerability
#################################################################
# Securitylab.ir
#################################################################
# Application Info:
# Name: eWebeditor
# Version: all version
#################################################################
# Vulnerability Info:
# Type: Directory Traversal
# Risk: Medium
#################################################################
# Vulnerability:
# http://site.com/admin/ewebeditor/admin/upload.asp?id=16&d_viewmode=&dir =./..
#################################################################
# Discoverd By: Pouya Daneshmand
# Website: http://securitylab.ir
# Contacts: info[at]securitylab.ir & whh_iran@yahoo.com
###################################################################
35 Responses
to “eWebEditor suffers from a directory traversal vulnerability”
32 Trackback(s)
- Nov 5, 2011: foundation repairs in Goodwins Corner IN
- Nov 6, 2011: Loreal professional hair color
- Nov 7, 2011: Free Psychic Reading
- Nov 8, 2011: cricut cartridges
- Nov 8, 2011: Healthy Choice coupon
- Nov 8, 2011: PDAs
- Nov 8, 2011: home improvement
- Nov 10, 2011: Chapter13 Illinois
- Nov 17, 2011: dove coupons
- Nov 19, 2011: government grants
- Nov 20, 2011: online public relations
- Dec 19, 2011: Carrier Parts
- Jan 6, 2012: roofing contractors Pleasant Hills OH
- Jan 6, 2012: Warlock
- Jan 8, 2012: my url
- Jan 10, 2012: delete fan facebook
- Jan 14, 2012: roofing in Enumclaw WA
- Jan 16, 2012: extraction thimbles
- Jan 17, 2012: deportiva
- Jan 18, 2012: portarollo
- Jan 19, 2012: Filter paper
- Jan 23, 2012: amazon is my niche Keyword.
- Jan 24, 2012: tanie czytanie
- Jan 25, 2012: http://wallinside.com/post-1253448.html
- Jan 26, 2012: Reifen
- Jan 27, 2012: law firm in Long Island, NY
- Jan 28, 2012: chicago limo service
- Jan 29, 2012: Alpha Warranty
- Feb 2, 2012: Top Penny Stocks
- Feb 3, 2012: Domain Brokerage
- Feb 5, 2012: loss of amenity
- Feb 5, 2012: supermarket injury
You must be logged in to post a comment.










































擦……这哪是伊朗人发现的。明明他们是这么被日的可好。前些日子我那哥们给我三个tip玩
tip1:[To Parent Directory] inurl:.gov.ir/
tip2:网站域名/html/js/editor/fckeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=connectors/php、aspx、jsp自己看网站环境选/connector.aspx、php、jsp自己选
tip3:上传失败用upload.asp?id=16&d_viewmode=&dir =./..厉遍目录找后台
st0p Reply:
February 9th, 2010 at 5:19 pm
唉,有点郁闷,不少人在转这个东西。
现在在网上想找到原作者有点难吧。郁闷。。
当时搜出来的29个.gov.ir都遭到毒手,就是这3个tip