CVE-2018-25178

Publication date

2026-03-06 12:19:08

Family

VulnCheck

State

PUBLISHED

Description

Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the file parameter. Attackers can send POST requests to showtif.php with arbitrary file paths in the file parameter to retrieve system files like configuration and initialization files.