Skip to content

admin/dump.php Arbitarily File Read Vulnerability #20

@R4ilgun

Description

@R4ilgun

In admin/dump.php
image
Ther is no detection for input,we can use php://filter with base64 encode to read .php or other files.
payload:http://test.com/admin/dump.php?ac=restore&id=../README.md

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions