Friday, March 16, 2012

Orinfor.gov.rw file upload vulnerability

Rwandan hackers has discovered a vulnerability in FCKeditor, which potentially can be exploited by malicious people to compromise a vulnerable system.

The problem is that it is possible to upload arbitrary files to a location inside the web root if the file extension does not match the list of denied file extensions. This can e.g. be exploited to upload and execute a malicious PHP script with the ".php.txt" file extension.

Successful exploitation requires that file uploads have been enabled in the "config.php" configuration file (not enabled by default).
orinfor.gov.rw uses FCKEDITOR

No comments:

Post a Comment