CS-Cart 1.3.3 Remote Code Execution

Details for achieving remote code execution on CS-Cart version 1.3.3, a really old version.

MD5 | 0df18b37ecb146e84ab2c6be59243438

# Exploit Title: CS-Cart authenticated RCE
# Date: 2020-09-22
# Exploit Author: 0xmmnbassel
# Vendor Homepage: https://www.cs-cart.com/e-commerce-platform.html
# Tested at: ver. 1.3.3
# Vulnerability Type: authenticated RCE

get PHP shells from
edit IP && PORT
Upload to file manager
change the extension from .php to .phtml
visit http://[victim]/skins/shell.phtml --> Profit. ...!

Related Posts