Hrsale 2.0.0 Local File Inclusion

Hrsale version 2.0.0 suffers from a local file inclusion vulnerability.

MD5 | 88dac6a7e7cede1e94e86a14088dd82f

# Exploit Title: Hrsale 2.0.0 - Local File Inclusion
# Date: 10/21/2020
# Exploit Author: Sosecure
# Vendor Homepage:
# Version: version 2.0.0

This exploit allow you to download any readable file from server with out permission and login session.

Payload :

1. Access to HRsale application and browse to download path with payload
2. Get /etc/passwd

Related Posts