OneFileCMS icon indicating copy to clipboard operation
OneFileCMS copied to clipboard

A single file cms - all in one file!

Results 16 OneFileCMS issues
Sort by recently updated
recently updated
newest added

1. Enter the page using the default username and password. ![1713406204_24286](https://github.com/Self-Evident/OneFileCMS/assets/31981526/d0ecf4e0-d56d-47ac-9d53-3357398e928b) 2. Click "New File" to create a new file named test.php. ![1713406296_6629](https://github.com/Self-Evident/OneFileCMS/assets/31981526/c9110b6a-6f28-4bfd-b7f1-9670ae77b609) 3. The content of test.php is ``...

Got asked by a friend yesterday what's wrong with the script, why isn't it working. So I checked it and found out that this array syntax seems not to work...

Remove syntax which was introduced in PHP5.4

1.Access http://127.0.0.1/OneFileCMS-master/onefilecms.php by username/password , then click 'OneFileCMS-master'. ![1](https://user-images.githubusercontent.com/24263756/51887869-22787480-23d0-11e9-883a-3deb64026812.png) 2.Then click 'onefilecms.php'. ![2](https://user-images.githubusercontent.com/24263756/51887892-2f956380-23d0-11e9-9627-ca355c0c7091.png) 3.You can see that there is no permission to edit 'onefilecms.php'. And then click 'copy'. ![3](https://user-images.githubusercontent.com/24263756/51887904-38863500-23d0-11e9-8b49-c6e4740aa3f6.png) 4.Nothing...

onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to access some secret file like passwd access `http://fragrant:30001/OneFileCMS/onefilecms.php?i=etc/&f=passwd&p=raw_view` ![image](https://user-images.githubusercontent.com/22767054/42225478-3458693c-7f0f-11e8-94f3-cc374d98860b.png)

access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password ![image](https://user-images.githubusercontent.com/22767054/42224826-96c5a32a-7f0d-11e8-81fe-bebd3494af8f.png) access http://fragrant:30001/OneFileCMS/onefilecms.php?i=var/www/html/&f=123.php&p=edit&p=deletefile ![image](https://user-images.githubusercontent.com/22767054/42224881-bdd58138-7f0d-11e8-9796-c963e9ef5d54.png) Click `Delete File(s)` ![image](https://user-images.githubusercontent.com/22767054/42225002-155834d2-7f0e-11e8-8a5e-ac2c9b54638b.png)

access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password ![image](https://user-images.githubusercontent.com/22767054/42224170-04f09de8-7f0c-11e8-8824-7134c8a954ef.png) Click `Upload File` -> abc.php -> `Browse` -> select abc.php -> Click `Upload` ![image](https://user-images.githubusercontent.com/22767054/42224282-46d3774e-7f0c-11e8-9e14-d8b31afad85c.png) ![image](https://user-images.githubusercontent.com/22767054/42224306-54d2b40e-7f0c-11e8-8c42-2c78e4622f07.png) access http://fragrant:30001/abc.php ![image](https://user-images.githubusercontent.com/22767054/42224341-686439d4-7f0c-11e8-94c1-ad0f34ff1e76.png)

onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to execute arbitrary PHP code via xxx .php filename on the New File screen access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password ![image](https://user-images.githubusercontent.com/22767054/42223064-6f53adea-7f09-11e8-8727-074ac65588db.png) Click `New File`...

Hello, after the Login the Interface show me: ``` ( ! ) $DEFAULT_PATH must be a decendant of, or equal to, $ACCESS_ROOT $ACCESS_ROOT = home/admin/web/xxx.de/public_html/test/ $DEFAULT_PATH = home/admin/web/xxx.de/public_html/test/ Warning: scandir(./home/admin/web/xxx.de/public_html/test/):...

Is it possible to show the image instead the icon, when the file is an image-file?

enhancement