Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25184. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Surreal ToDo 0.6.1.2 by manipulating the 'content' parameter in the URL to read arbitrary files from the server. The provided HTTP request shows a successful retrieval of the 'win.ini' file, confirming the vulnerability.
Description
Surreal ToDo 0.6.1.2 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the content parameter. Attackers can supply directory traversal sequences through the content parameter in index.php to access sensitive system files like configuration and initialization files.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in Surreal ToDo 0.6.1.2 by manipulating the 'content' parameter in the URL to read arbitrary files from the server. The provided HTTP request shows a successful retrieval of the 'win.ini' file, confirming the vulnerability.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N