phpFileManager 1.7.8 Local File Inclusion via index.php
Vulnerability Description
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25632
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Murat Kalafatoglu
References
More from Sourceforge
View All →Affected Vendor
Sourceforge
View all reports →