header-logo
Suggest Exploit
vendor:
Holiday Travel Portal
by:
Sid3^effects
7.5
CVSS
HIGH
Upload Vulnerability
CWE
Product Name: Holiday Travel Portal
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
2010

Holiday Travel Portal Upload Vulnerability

The vulnerability allows an attacker to upload arbitrary files to the Holiday Travel Portal website. This can lead to remote code execution or other malicious activities.

Mitigation:

The vendor should implement proper input validation and file handling techniques to prevent unauthorized file uploads. Users should update to the latest version of the software.
Source

Exploit-DB raw data:

==========================================================
            Holiday Travel Portal Upload Vulnerability  
==========================================================
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : Inj3ct0r.com                                  0
1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1
0                                                                      0
1               ##########################################             1
0               I'm Sid3^effects member from Inj3ct0r Team             1
1               ##########################################             0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

Name : Holiday Travel Portal Upload Vulnerability 
Date : june, 8 2010
Vendor url :http://www.tourismscripts.com/scripts/
Price: 299 Euro
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
special thanks to : r0073r (inj3ct0r.com),MaYur,LiquidWorm,gunslinger_
greetz to :All ICW members.

###############################################################################################################
Description:

Our comfortable Accommodation Hotel Booking Portal for all kind of accommodation
hotels, hostels, apartments, guest house, finca, motels .....
villas, houses, flats, Yachts, Tours, Cities ....

###############################################################################################################
Xploit: Upload Vulnerability

STEP 1 : REgister as a user :)

STEP 2 : demo url for loggin in 

DEMO URL : http://server/user/?

STEP 3 : Once logged in go to edit profile to upload your evil script with an extension .php.jpg :)

STEP 4 : Go to your shell
  
DEMO URL : http://server/user/uploads/small_thumbs/testphpjpeg.php.txt.txt.txt

STEP 5 : And there your are :)
         
###############################################################################################################
#Sid#^effects