Self-Evident / OneFileCMS

A single file cms - all in one file!
http://onefilecms.com/
165 stars 57 forks source link

onefilecms.php in OneFileCMS can be illegally modified (Administrator Privilege) #51

Open r00tSe7en opened 5 years ago

r00tSe7en commented 5 years ago

1.Access http://127.0.0.1/OneFileCMS-master/onefilecms.php by username/password , then click 'OneFileCMS-master'.

1

2.Then click 'onefilecms.php'.

2

3.You can see that there is no permission to edit 'onefilecms.php'. And then click 'copy'.

3

4.Nothing to do ,and click 'copy' again.

4

5.And you can see ,the file is ready for editing and saving. As following picture shows.

5

6.After saving ,refresh the home page,found that has been modified.

6