[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Korean GHBoard Multiple Vulnerabilities by Xcross87

Software : Korean GHBoard
Site : http://www.ghlab.com/
Found by : Xcross87
1. File Upload Vulnerability
Xploit :

2. FlashUpload component File Upload and File Download Vulnerability
Upload Xploit :
Not allow upload php,jsp,html
But attacker can download source and remove javascript code which check for file type and upload easily.
Uploaded file is located in :

Download Xploit :
You can download any file from server :
Sample :

3. FCK Inclusion :
All version of GHBoard includes FCKEditor package so attacker can use upload vulz of FCKEditor to up shell to server.

=== Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===