header-logo
Suggest Exploit
vendor:
ECommerce-Multi-Vendor Software
by:
İhsan Şencan
8,8
CVSS
HIGH
Arbitrary Shell Upload
78
CWE
Product Name: ECommerce-Multi-Vendor Software
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017

Profile Arbitrary Shell Upload

Register in the site, login, go to profile, upload an empty file .htaccess and Shell.php, and then go to http://site.com/Shell.php

Mitigation:

Ensure that the file upload feature is properly secured and only allows the upload of files with the correct MIME type and extension.
Source

Exploit-DB raw data:

# # # # # 
# Vulnerability:(Profile) Arbitrary Shell Upload
# Google Dork: ECommerce-Multi-Vendor Software
# Date:11.01.2017
# Vendor Homepage: http://www.tibsolutions.com/multi-vendor/
# Script Name: ECommerce-Multi-Vendor Software
# Script Buy Now: http://www.tibsolutions.com/multi-vendor/
# Author: İhsan Şencan
# Author Web: http://ihsan.net
# Mail : ihsan[beygir]ihsan[nokta]net
# # # # # 
#Exploit :
#Register in site ... and login 
#Goto profil
#Empty file .htaccess and Shell.php...