The admin() function in upload/admin/controller/common/security.php is vulnerable to PHP static code injection because $name user-controlled variable is placed inside $base_new, which is then written inside a new config.php file, without proper escape or validation.
Full article at https://0xbro.red/disclosures/disclos...
=== Timestamp ===
00:00:00 - Set-up overview
00:00:19 - Exploitation
If you enjoyed the video leave a like and subscribe to my channel!
For writeups in text format or other articles related to Ethical Hacking go to my blog: https://maoutis.github.io/
---
Would you like to support my work? Offer me a virtual coffee :)
https://www.buymeacoffee.com/0xbro
Check out my socials:
Linkedin: / mattia-0xbro-brollo-b4129614b
Mastodon: https://infosec.exchange/@0xbro
Twitter: / 0xbro1
En esta página del sitio puede ver el video en línea OpenCart Static Code Injection in common/security.admin de Duración hora minuto segunda en buena calidad , que subió el usuario 0xbro 14 noviembre 2023, comparta el enlace con amigos y conocidos, en youtube este video ya ha sido visto 449 veces y le gustó 6 a los espectadores. Disfruta viendo!