OpenCart Static Code Injection in common/security.admin

Veröffentlicht am: 14 November 2023
auf dem Kanal: 0xbro
449
6

The admin() function in upload/admin/controller/common/security.php is vulnerable to PHP static code injection because $name user-controlled variable is placed inside $base_new, which is then written inside a new config.php file, without proper escape or validation.

Full article at https://0xbro.red/disclosures/disclos...

=== Timestamp ===
00:00:00 - Set-up overview
00:00:19 - Exploitation

If you enjoyed the video leave a like and subscribe to my channel!
For writeups in text format or other articles related to Ethical Hacking go to my blog: https://maoutis.github.io/
---
Would you like to support my work? Offer me a virtual coffee :)
https://www.buymeacoffee.com/0xbro

Check out my socials:
Linkedin:   / mattia-0xbro-brollo-b4129614b  
Mastodon: https://infosec.exchange/@0xbro
Twitter:   / 0xbro1  


Auf dieser Seite können Sie das Online-Video OpenCart Static Code Injection in common/security.admin mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer 0xbro 14 November 2023 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 449 Mal angesehen und es wurde von 6 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!