Exploits / Vulnerability Discovered : 2022-02-21 |
Type : webapps |
Platform : php
This exploit / vulnerability Microweber 1.2.11 remote code execution (rce) (authenticated) is for educational purposes only and if it is used you will do on your own risk!
# Step To Reproduce
- Login using Admin Creds.
- Navigate to User Section then Add/Modify Users
- Change/Add image of profile and Select a Crafted Image file
- Crafted image file Aka A image file which craft with PHP CODES for execution
- File Extension of Crafted File is PHP7 like "Sample.php7"
- Path of Uploaded Crafted SHELL https://localhost/userfiles/media/default/shell.php7