Exploits / Vulnerability Discovered : 2020-05-05 |
Type : webapps |
Platform : php
This exploit / vulnerability Phreebooks erp 5.2.5 remote command execution is for educational purposes only and if it is used you will do on your own risk!
There are no file extension controls on Image Manager (5.2.4) and on Backup
Restore. If an authorized user is obtained, it is possible to run a
malicious PHP file on the server.
--------------------------------------------------------------------------------------
One of the Vulnerable File: (backup.php)
-----------------------------------------