phpFileManager
cpe:2.3:a:phpfilemanager_project:phpfilemanager:*:*:*:*:*:*:*
- <= 1.7.8
A local file inclusion vulnerability has been identified in phpFileManager version 1.7.8. This vulnerability allows unauthenticated attackers to read arbitrary files from the server by manipulating the action, fm_current_dir, and filename parameters in GET requests to index.php. Exploitation of this vulnerability could lead to the disclosure of sensitive files, such as /etc/passwd.
Exploitation of this vulnerability allows for local file inclusion, enabling attackers to read arbitrary files from the server.
To reproduce this vulnerability, send a GET request to index.php with the action parameter set to 3, the fm_current_dir parameter set to the directory containing the target file (e.g., /etc/), and the filename parameter set to the name of the file to be accessed (e.g., passwd).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.