This is a writeup describing a Remote File Inclusion (RFI) vulnerability in MassMirror Uploader. It provides a proof-of-concept URL to exploit the vulnerability by injecting a malicious URL into the `GLOBALS[MM_ROOT_DIRECTORY]` parameter.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target:MassMirror Uploader (version unspecified)
No auth needed
Prerequisites:Access to the vulnerable endpoint · A hosted malicious file to include