FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into accessible directories, and execute arbitrary commands through the extracted PHP files.
References
| Link | Resource |
|---|---|
| https://github.com/leefish/filethingie/archive/master.zip | Product |
| https://www.exploit-db.com/exploits/47349 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/filethingie-arbitrary-file-upload-via-ft2-php | Third Party Advisory |
Configurations
History
13 Apr 2026, 14:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/leefish/filethingie/archive/master.zip - Product | |
| References | () https://www.exploit-db.com/exploits/47349 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/filethingie-arbitrary-file-upload-via-ft2-php - Third Party Advisory | |
| First Time |
Leefish
Leefish file Thingie |
|
| Summary |
|
|
| CPE | cpe:2.3:a:leefish:file_thingie:*:*:*:*:*:*:*:* |
11 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
11 Mar 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-11 19:16
Updated : 2026-04-13 14:25
NVD link : CVE-2019-25471
Mitre link : CVE-2019-25471
CVE.ORG link : CVE-2019-25471
JSON object : View
Products Affected
leefish
- file_thingie
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
