This is a writeup describing a Remote File Inclusion (RFI) vulnerability in Dros software. It provides URLs where the vulnerability can be exploited by injecting malicious code via the 'smarty' or '_compile_file' parameters.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target:Dros (version not specified)
No auth needed
Prerequisites:Access to the vulnerable Dros application · Ability to craft malicious URLs with RFI payloads