Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-49544 — Customer Support System 1.0 - Local File Inclusion | Kitploit
Tools/GitHubGitHub/geraldoalcantara/cve-2023-49544
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubgeraldoalcantara/cve-2023-49544

CVE-2023-49544

Customer Support System 1.0 - Local File Inclusion

View Repository
412 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-49544

Customer Support System 1.0 - Local File Inclusion

Description: Customer Support System 1.0 is vulnerable to Local File Inclusion. An authenticated user has the capability to access and read PHP files from the operating system by exploiting a Local File Inclusion (LFI) vulnerability through the wrapper filter.

Vulnerable Product Version: Customer Support System 1.0
CVE Author: Geraldo Alcântara
Date.: 28/11/2023
Confirmed on: 19/12/2023
CVE: CVE-2023-49544
Tested on: Windows

Steps to reproduce:

  1. Log in to the application with any user.
  2. Modify the vulnerable "page" parameter to exploit the vulnerability.
    Payload: php://filter/convert.base64-encode/resource=C:\xampp\htdocs\customer_support\db_connect

Exploiting the vulnerability and retrieving the content of the PHP file in base64. lfi01

Reading the content of the file (Base64 decoded). lfi02

Discoverer(s)/Credits:
Geraldo Alcântara

Download Tool