bg5sbk/MiniCMS

there is a file inclusion vulnerability

yuansec opened this issue · 1 comments

In this page "MiniCMS-master\mc-admin\page-edit.php" have a file inclusion vulnerability.
1.The parameter “$page_state”get from POST,it is Controllable.
图片

2.The parameter"index_file" is Controllable too.
图片

3.Causes File Inclusion vulnerabilities

For example,use parameter POST_“state”="../1.jpg" or “../../../../../etc/passwd” to attack