Tiny File Manager <= 2.4.6 - Remote Code Execution (Authenticated)

🚨 About the Exploit
This is a Bash-based authenticated Remote Code Execution (RCE) exploit for Tiny File Manager versions <= 2.4.6, vulnerable under CVE-2021-40964.
The script leverages:
- Weak upload validation and webroot disclosure,
- An arbitrary file upload vulnerability, leading to PHP code execution.
📌 Details
- Exploit Title: Tiny File Manager <= 2.4.6 - Remote Code Execution (RCE)
- CVE: CVE-2021-40964
- Author:
Z3R0 (0x30)
- Vulnerable Version: ≤ 2.4.6
- Authentication Required: Yes (Admin credentials)
⚙️ Prerequisites
Ensure the following tools are installed:
sudo apt install curl jq