bg5sbk / MiniCMS

至简的个人网站内容管理系统
http://1234n.com/?projects/minicms/
227 stars 61 forks source link

there is a file inclusion vulnerability #30

Closed yuansec closed 3 years ago

yuansec commented 5 years ago

In this page "MiniCMS-master\mc-admin\page-edit.php" have a file inclusion vulnerability. 1.The parameter “$page_state”get from POST,it is Controllable. 图片

2.The parameter"index_file" is Controllable too. 图片

3.Causes File Inclusion vulnerabilities

yuansec commented 5 years ago

For example,use parameter POST_“state”="../1.jpg" or “../../../../../etc/passwd” to attack