============================================================================================================================================= | # Title : Student Enrollment v1.0 Remote File Upload Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 125.0.1 (64 bits) | | # Vendor : https://download-media.code-projects.org/2020/06/Student_Enrollment_In_PHP_With_Source_Code.zip | ============================================================================================================================================= poc : [+] Dorking İn Google Or Other Search Enggine. [+] The following html code uploads a executable malicious file remotely . [+] use payload : Upload Profile Photo

Upload Profile Photo



[+] Go to the line 10. Set the target site link Save changes and apply . [+] save code as poc.html [+] Link to the uploaded files : admin/index.php?page=user-profile [+] path : http://127.0.0.1/student-php-enroolment/admin/images/ evli.php Greetings to :===================================================================================== jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)| ===================================================================================================