bg5sbk/MiniCMS

Local File Inclusion vulnerability in v1.9

cilan2 opened this issue · 0 comments

PHP Version <5.3.4
Local File Inclusion vulnerability in page-edit.php
image
$data = unserialize(file_get_contents($file_path));
$page_old_state = $data['state'];
$index_file = '../mc-files/pages/index/'.$page_old_state.'.php'
require $index_file

write a page or article with content:
image
use burp to