再访问根目录下的_whatsnew.html获得版本信息。
或者可以访问editor/dialog/fck_about.html来获取。在测试上传页修改Connector选项为php,然后直接上传php文件,用burp抓包在文件名最后加空格,即可绕过FCK编辑器File类型上传文件的黑名单限制。提示这个就是上传成功了。至于文件被上传到哪里了,可以访问下面这个链接获取路径:/editor/filemanager/browser/default/connectors/php/connector.php?Command=GetFoldersAndFilesType=FileCurrentFolder=/根据获取到的路径直接访问文件即可。不是所有fck都是这个测试上传页路径,大家可以把下面这些加进扫目录的字典里。当然有时实在没有测试上传页也可以对着上传接口直接构造上传请求,收集到的上传接口也在下面了。FCKeditor/editor/filemanager/browser/default/connectors/test.htmlFCKeditor/editor/filemanager/upload/test.htmlFCKeditor/editor/filemanager/connectors/test.htmlFCKeditor/editor/filemanager/connectors/uploadtest.htmlFCKeditor/_samples/default.htmlFCKeditor/_samples/asp/sample01.aspFCKeditor/_samples/asp/sample02.aspFCKeditor/_samples/asp/sample03.aspFCKeditor/_samples/asp/sample04.aspFCKeditor/_samples/default.htmlFCKeditor/editor/fckeditor.htmFCKeditor/editor/fckdialog.htmlFCKeditor/editor/filemanager/browser/default/connectors/asp/connector.asp?Command=GetFoldersAndFilesType=ImageCurrentFolder=/FCKeditor/editor/filemanager/browser/default/connectors/php/connector.php?Command=GetFoldersAndFilesType=ImageCurrentFolder=/FCKeditor/editor/filemanager/browser/default/connectors/aspx/connector.aspx?Command=GetFoldersAndFilesType=ImageCurrentFolder=/FCKeditor/editor/filemanager/browser/default/connectors/jsp/connector.jsp?Command=GetFoldersAndFilesType=ImageCurrentFolder=/FCKeditor/editor/filemanager/browser/default/browser.html?Type=ImageConnector=