CVE-2018-25178
HIGHrul10 easyndexer 1.0 - Unauthenticated Arbitrary File Download via showtif.php File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25178. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file download vulnerability in Easyndexer 1.0 via the 'showtif.php' script, allowing an attacker to retrieve sensitive files (e.g., C:/Windows/win.ini) by manipulating the 'file' parameter. The PoC includes a crafted HTTP POST request and server response confirming the vulnerability.
Description
Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the file parameter. Attackers can send POST requests to showtif.php with arbitrary file paths in the file parameter to retrieve system files like configuration and initialization files.
Exploits (1)
The exploit demonstrates an arbitrary file download vulnerability in Easyndexer 1.0 via the 'showtif.php' script, allowing an attacker to retrieve sensitive files (e.g., C:/Windows/win.ini) by manipulating the 'file' parameter. The PoC includes a crafted HTTP POST request and server response confirming the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N