CVE-2017-12761
HIGHWebFile Explorer 1.0 - SQL Injection and Arbitrary File Download via download.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-12761. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in WebFile Explorer 1.0 due to improper file path handling in the 'download.php' script. The PoC shows how an attacker can download any file by manipulating the 'id' parameter.
Description
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is: http://speicher.example.com/envato/codecanyon/demo/web-file-explorer/download.php?id=WebExplorer/../config.php.
Exploits (1)
This exploit demonstrates an arbitrary file download vulnerability in WebFile Explorer 1.0 due to improper file path handling in the 'download.php' script. The PoC shows how an attacker can download any file by manipulating the 'id' parameter.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N