logo

Local File Inclusion Vulnerability Explained (with a bit of pentesting)

ID: 385efba0-1164-5a89-983f-740ee8fd19ec

STIX ID: report--385efba0-1164-5a89-983f-740ee8fd19ec

Feed Name: On the Hunt

Threat Score
55/100

Date Published: 2019-12-31

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This post is a hands-on walkthrough of exploiting a PHP Local File Inclusion (LFI) vulnerability on a PWNLab VM: the author uses vulnerability scanning and php://filter to read source files and database credentials, logs in to the application, bypasses image upload whitelists by prepending "GIF89;" to a PHP reverse shell renamed with a .gif extension, uploads the shell, and triggers execution via a cookie-based include to obtain a remote shell and then attempts local privilege escalation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.