OneFileCMS icon indicating copy to clipboard operation
OneFileCMS copied to clipboard

onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to execute arbitrary PHP code via xxx .php filename on the New File screen

Open havysec opened this issue 7 years ago • 0 comments

onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to execute arbitrary PHP code via xxx .php filename on the New File screen

access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password

image

Click New File -> 123.php -> Create

image

image

Click SAVE CHANGES -> access http://fragrant:30001/123.php

image

havysec avatar Jul 03 '18 13:07 havysec