AtomatiCMS - Upload Arbitrary File

Author: Abysssec
type: webapps
platform: asp
port: 
date_added: 2010-09-28  
date_updated: 2010-09-28  
verified: 1  
codes:   
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comatomaticms10_all.zip  

raw file: 15139.txt  
'''
  __  __  ____         _    _ ____
 |  \/  |/ __ \   /\  | |  | |  _ \
 | \  / | |  | | /  \ | |  | | |_) |
 | |\/| | |  | |/ /\ \| |  | |  _ <
 | |  | | |__| / ____ \ |__| | |_) |
 |_|  |_|\____/_/    \_\____/|____/

'''



Abysssec Inc Public Advisory


  Title            :  AtomatiCMS Upload arbitrary file Vulnerability
  Affected Version :  AtomatiCMS 10_all
  Discovery        :  www.abysssec.com
  Vendor	   :  http://www.atomaticsoftware.com
  Download Links   :  http://sourceforge.net/projects/atomaticms/


Description :
===========================================================================================
  This version of AtomatiCMS have Upload arbitrary file Vulnerability  with fckEditor
  in this Paths:

       http://Example.com/FCKeditor/editor/filemanager/browser/default/connectors/test.html
       http://Example.com/FCKeditor/editor/filemanager/upload/test.html


   Which your files will be in this path:
       .../UserFiles/



===========================================================================================