Skip to content

Instantly share code, notes, and snippets.

@virendratiwari03
Created November 4, 2020 06:33
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save virendratiwari03/800f96271f22c0c2f5aea126c7f1f170 to your computer and use it in GitHub Desktop.
Save virendratiwari03/800f96271f22c0c2f5aea126c7f1f170 to your computer and use it in GitHub Desktop.
Product: Microweber
Product Version: 1.1.18
Vulnerability: Unrestricted File upload
Description:
An Unrestricted File Upload Vulnerability in the Microweber version 1.1.18 allows remote attackers to upload any extensions like php, exe in the profile upload section.
Attack Type: Local
Impact:
An attacker with the ability to upload a malicious file to the application can set up drive-by-download attacks, deface the website, or gain access to the file system through a web shell.
Reference:
https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload
https://null-byte.wonderhowto.com/how-to/upload-shell-web-server-and-get-root-rfi-part-1-0162818/
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment