Skip to content

Latest commit

 

History

History
43 lines (24 loc) · 1.66 KB

README.md

File metadata and controls

43 lines (24 loc) · 1.66 KB

Tittle: Online Banking System LFI.

Author: (Erik451)

Software Link: Online Banking System

Version: OBS 1.0

Description: The parameter "p" and "page" includes files. An unauthenticated user can read internal php files of the web. LFI to Privilege Escalation

  • Null session account to admin
  • Payload used: http://web.com/banking/?p=<any_phpfile>

Steps to reproduce:

nullsession

adminpage

  • 3- Change the admin password

changepass

  • 4- Login as administrator

login

  • 5- Admin panel

adminpanel

Other Payload:

Reading info.php

infophp