phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.
Metrics
Affected Vendors & Products
References
History
Tue, 24 Mar 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server. | |
| Title | phpFileManager 1.7.8 Local File Inclusion via index.php | |
| First Time appeared |
Dulldusk
Dulldusk phpfilemanager |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:dulldusk:phpfilemanager:1.7.8:*:*:*:*:*:*:* | |
| Vendors & Products |
Dulldusk
Dulldusk phpfilemanager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-24T11:27:06.388Z
Reserved: 2026-03-24T11:02:26.100Z
Link: CVE-2019-25632
No data.
Status : Received
Published: 2026-03-24T12:16:03.597
Modified: 2026-03-24T12:16:03.597
Link: CVE-2019-25632
No data.
OpenCVE Enrichment
No data.