You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
onelastcrush has discovered a vulnerability classified as critical in Complete E-Commerce Site in PHP/MySQLi V1.0. The function upload is affected. This operation will result in unrestricted uploads. Remote attacks can cause RCE.
Vulnerability Details
Complete E-Commerce Site in PHP/MySQLi V1.0
Vulnerable File: admin/products_photo.php
Parameter Names: filename
Attack Type: Remote
Description
A vulnerability, which was classified as critical, has been found in Complete E-Commerce Site in PHP/MySQLi. This issue affects the function upload. The manipulation with an unknown input leads to a unrestricted upload vulnerability.
Note
To exploit this vulnerability, users need to log in, and the website allows any user to register by default.
Complete E-Commerce Site in PHP/MySQLi - Arbitrary file vulnerability uploading leads to command execution
Vendor Homepage
Software Link
Overview
Vulnerability Details
Description
Note
Proof of Concept (PoC) :
Location of vulnerabilities in source code
The text was updated successfully, but these errors were encountered: