HongCMS
0x01 Delete&&download Anything(Admin Privilege)
/admin/controllers/database


There is a ajax() which can delete or download anything.
The ForceStringFrom() is to receive get or post from user,if we get action is delete and filename is test.txt(default path is /system/backup):


Delete successfully.
We can delete anthing:


0x02 Download Anything(Admin Privilege)

Just modify the param we get.