OpenCart Static Code Injection in common/security.admin

Pubblicato il: 14 novembre 2023
sul canale di: 0xbro
449
6

The admin() function in upload/admin/controller/common/security.php is vulnerable to PHP static code injection because $name user-controlled variable is placed inside $base_new, which is then written inside a new config.php file, without proper escape or validation.

Full article at https://0xbro.red/disclosures/disclos...

=== Timestamp ===
00:00:00 - Set-up overview
00:00:19 - Exploitation

If you enjoyed the video leave a like and subscribe to my channel!
For writeups in text format or other articles related to Ethical Hacking go to my blog: https://maoutis.github.io/
---
Would you like to support my work? Offer me a virtual coffee :)
https://www.buymeacoffee.com/0xbro

Check out my socials:
Linkedin:   / mattia-0xbro-brollo-b4129614b  
Mastodon: https://infosec.exchange/@0xbro
Twitter:   / 0xbro1  


In questa pagina del sito puoi guardare il video online OpenCart Static Code Injection in common/security.admin della durata di ore minuti seconda in buona qualità , che l'utente ha caricato 0xbro 14 novembre 2023, condividi il link con amici e conoscenti, su youtube questo video è già stato visto 449 volte e gli è piaciuto 6 spettatori. Buona visione!