header-logo
Suggest Exploit
vendor:
Download Management
by:
SecurityFocus
7.5
CVSS
HIGH
Local File Include
98
CWE
Product Name: Download Management
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Download Management for PHP-Fusion Local File Include Vulnerabilities

Download Management for PHP-Fusion is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these issues may allow an attacker to access potentially sensitive information and execute arbitrary local scripts in the context of the affected application.

Mitigation:

Input validation should be used to ensure that user-supplied input is properly sanitized.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/27618/info

Download Management for PHP-Fusion is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.

Exploiting these issues may allow an attacker to access potentially sensitive information and execute arbitrary local scripts in the context of the affected application.

These issues affect Download Management 1.00; other versions may also be vulnerable. 

http://example.com/infusions/download_management/infusion.php?settings[locale]=LFI%00
http://example.com/infusions/download_management/download_management.php?settings[locale]=LFI%00