vendor:
phpFileManager version 0.9.8
by:
John Page ( hyp3rlinx )
8.8
CVSS
HIGH
CSRF Remote Backdoor Shell
352
CWE
Product Name: phpFileManager version 0.9.8
Affected Version From: 2000.9.8
Affected Version To: 2000.9.8
Patch Exists: Yes
Related CWE: N/A
CPE: a:phpfm:phpfm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1
2015
CSRF Remote Backdoor Shell
PHP File Manager is vulnerable to creation of arbitrary files on server via CSRF which we can use to create remote backdoor shell access if victim clicks our malicious linx or visits our malicious webpages. To create backdoor shell we will need to execute two POST requests 1- to create PHP backdoor shell 666.php 2- inject code and save to the backdoor we just created.
Mitigation:
Upgrade to the latest version of phpFileManager.