Skip to content

onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to execute arbitrary PHP code via xxx .php filename on the Upload File screen #48

@havysec

Description

@havysec

access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password

image

Click Upload File -> abc.php -> Browse -> select abc.php -> Click Upload

image

image

access http://fragrant:30001/abc.php

image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions