This Metasploit module exploits a vulnerability in the TinyMCE/tinybrowser plugin. This plugin is not secured in version 0.9 of VAMCart and allows the upload of files on the remote server. By renaming the uploaded file this vulnerability can be used to upload/execute code on the affected system.
2f631d7a476c9b413ae2de8686ab1f98d4e0e9c4ff4f224e34949b05e6bbf3c0
Secunia Security Advisory - A vulnerability has been reported in VamCart, which can be exploited by malicious people to conduct cross-site request forgery attacks.
0d08790563db0d40bc8473c4aea9beccf9e86ba2dd89ceebbae906bcf3c21967
VamCart version 0.9 suffers from a cross site request forgery vulnerability.
44b4331ea7a4adfb5da06983201511d8e96dbbfa64003c6c419310507d3d5a89
VamCart CMS version 0.9 suffers from multiple cross site scripting vulnerabilities.
20b70ae83034a770d8f15b30a15883ea7321b714bb164532950b8650047e65d1
VANCart-InternetShop version 0.9 suffers from cross site request forgery and shell upload vulnerabilities.
a3d1a0eb4bb484d54b974426fd346ef862dfc26b4788bc1577f86886d324b2b8