This is a writeup describing a Remote File Include (RFI) vulnerability in phpOnDirectory version 1.0. It provides URLs to exploit the vulnerability by injecting malicious scripts via the CONST_INCLUDE_ROOT parameter.
Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target:phpOnDirectory <= v.1.0
No auth needed
Prerequisites:Access to the target URL · Ability to host or reference a malicious script