vendor:
Online Ordering System
by:
Suraj Bhosale
9.8
CVSS
HIGH
Arbitrary File Upload to Remote Code Execution
434
CWE
Product Name: Online Ordering System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10, XAMPP
2021
Online Ordering System 1.0 – Arbitrary File Upload to Remote Code Execution
An attacker can upload a malicious file to the web server by exploiting the arbitrary file upload vulnerability in the Online Ordering System 1.0. This vulnerability can be exploited by an attacker to execute arbitrary code on the web server.
Mitigation:
The application should validate the file type before uploading it to the server. The application should also restrict the file size and file type to be uploaded.