The exploit demonstrates a path traversal vulnerability in eFront 3.6.15 via the view_file.php module, allowing unauthenticated attackers to read arbitrary files on the server by manipulating the 'file' parameter with directory traversal sequences.
Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:eFront 3.6.15 and lower
No auth needed
Prerequisites:Access to the target's view_file.php endpoint