vendor:
Mini File Host
by:
Scary-Boys, shinmai
N/A
CVSS
N/A
Local File Inclusion through POST requests (pages/upload.php)
N/A
CWE
Product Name: Mini File Host
Affected Version From: 1.2.2001
Affected Version To: 1.2.2001
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Mini File Host (1.2.1 “Security Fixed release” and earlier)
The same language=LFI vulnerability is found in 1.2 is present in the latest version POST has to be used to exploit instead of GET. This POC is to be used as follows: perl mfh121.pl -f FILENAME.PHP -h HOSTNAME -e PATH TO MFH FILENAME.PHP is uploaded to the target script, and then executed through LFI with a POST request.
Mitigation:
N/A