This exploit demonstrates a Local File Inclusion (LFI) vulnerability in webEdition CMS 6.1.0.2. The vulnerability arises from improper handling of the `DOCUMENT_ROOT` parameter in `index.php`, allowing an attacker to include arbitrary local files via null byte injection.
Classification
Working Poc 90%
Attack Type
Lfi
Complexity
Trivial
Reliability
Reliable
Target:webEdition CMS 6.1.0.2
No auth needed
Prerequisites:Access to the target web application