Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

LFI on OpenClinic Admin #8

Closed
u0pattern opened this issue Sep 15, 2019 · 0 comments
Closed

LFI on OpenClinic Admin #8

u0pattern opened this issue Sep 15, 2019 · 0 comments
Assignees
Labels

Comments

@u0pattern
Copy link

PoC : http://localhost/openClinic/shared/view_source.php?file=../config/database_constants.php
Impact : Anyone login to the the admin account can read files from server like config and maybe can get RCE.
Fix : remove the view_source.php or you can blacklist the dot and slashes .

Hitman ALHarbi | Blackfoxs Team .

@jact jact self-assigned this Sep 17, 2019
@jact jact closed this as completed in 7821ba2 Sep 17, 2019
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants