Korean GHBoard Multiple Vulnerabilities

2007.10.31
Credit: Xcross87
Risk: High
Local: No
Remote: Yes
CWE: N/A

Software : Korean GHBoard Site : http://www.ghlab.com/ Found by : Xcross87 1. File Upload Vulnerability Xploit : victim.com/ghboard/component/upload.jsp 2. FlashUpload component File Upload and File Download Vulnerability Upload Xploit : victim.com/ghboard/component/flashupload/upload.html Not allow upload php,jsp,html But attacker can download source and remove javascript code which check for file type and upload easily. Uploaded file is located in : victim.com/ghboard/component/flashupload/data/upload_filename.xxx Download Xploit : You can download any file from server : victim.com/ghboard/component/flashupload/download.jsp?name=[file_name] Sample : victim.com/ghboard/component/flashupload/download.jsp?name=../config.jsp 3. FCK Inclusion : All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server. === Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2019, cxsecurity.com

 

Back to Top