Cscart 1.3.3 authenticated rce Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2020-10-16 | Type : webapps | Platform : php
This exploit / vulnerability Cscart 1.3.3 authenticated rce is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...

# Exploit Title: CS-Cart authenticated RCE
# Date: 2020-09-22
# Exploit Author: 0xmmnbassel
# Vendor Homepage:
# Tested at: ver. 1.3.3
# Vulnerability Type: authenticated RCE

get PHP shells from
edit IP && PORT
Upload to file manager
change the extension from .php to .phtml
visit http://[victim]/skins/shell.phtml --> Profit. ...!