nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28136 CVE-2020-28136
HIGH
Tourism Management System 1.0 - Arbitrary File Upload
Record summary
CVE-2020-28136 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
An Arbitrary File Upload is discovered in SourceCodester Tourism Management System 1.0 allows the user to conduct remote code execution via admin/create-package.php vulnerable page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTourism Management System 1.0 - Arbitrary File UploadExploitDB exploitby Ankita PalNot analyzed1 file
References
3phpgurukul.com
https://phpgurukul.com/tourism-management-system-free-download exploit-db.com
https://www.exploit-db.com/exploits/48892