This exploit demonstrates a Remote File Include (RFI) vulnerability in Public Media Manager <= 1.3. The vulnerability exists in the `calmenu.php` file, which unsafely includes a file specified by the `forms_dir` parameter, allowing an attacker to execute arbitrary code by including a remote shell.
Classification
Working Poc 90%
Target:
Public Media Manager <= 1.3
No auth needed
Prerequisites:
Remote file inclusion must be enabled on the target server · Attacker must be able to host a malicious file on a remote server