Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [Vulz]  PHP Basic Multiple Vulnerabilities by Xcross87 & Alucar

  [Vulz] Seeblick 1.0 Beta File Upload Vulz

  [Vulz] eFileMan 7.x Multiple Vulnerabilities by Xcross87

  [Vulz] eLouai's Download Script Remote File Download Vulnerability

From:pete.houston.17187_(at)_gmail.com <pete.houston.17187_(at)_gmail.com>
Date:23.10.2007
Subject:Korean GHBoard Multiple Vulnerabilities by Xcross87

Software : Korean GHBoard
Site : http://www.ghlab.com/
Found by : Xcross87
1. File Upload Vulnerability
Xploit :
victim.com/ghboard/component/upload.jsp

2. FlashUpload component File Upload and File Download Vulnerability
Upload Xploit :
victim.com/ghboard/component/flashupload/upload.html
Not allow upload php,jsp,html
But attacker can download source and remove javascript code which check for file type and upload easily.
Uploaded file is located in :
victim.com/ghboard/component/flashupload/data/upload_filename.xxx

Download Xploit :
You can download any file from server :
victim.com/ghboard/component/flashupload/download.jsp?name=[file_name]
Sample :
victim.com/ghboard/component/flashupload/download.jsp?name=../config.jsp

3. FCK Inclusion :
All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server.

=== Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru