The admin() function in upload/admin/controller/common/security.php is vulnerable to PHP static code injection because $name user-controlled variable is placed inside $base_new, which is then written inside a new config.php file, without proper escape or validation.
Full article at https://0xbro.red/disclosures/disclos...
=== Timestamp ===
00:00:00 - Set-up overview
00:00:19 - Exploitation
If you enjoyed the video leave a like and subscribe to my channel!
For writeups in text format or other articles related to Ethical Hacking go to my blog: https://maoutis.github.io/
---
Would you like to support my work? Offer me a virtual coffee :)
https://www.buymeacoffee.com/0xbro
Check out my socials:
Linkedin: / mattia-0xbro-brollo-b4129614b
Mastodon: https://infosec.exchange/@0xbro
Twitter: / 0xbro1
In questa pagina del sito puoi guardare il video online OpenCart Static Code Injection in common/security.admin della durata di ore minuti seconda in buona qualità , che l'utente ha caricato 0xbro 14 novembre 2023, condividi il link con amici e conoscenti, su youtube questo video è già stato visto 449 volte e gli è piaciuto 6 spettatori. Buona visione!