CVE-2021-28294
CRITICALOnline Ordering System 1.0 - Unrestricted File Upload via initiateorder.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-28294. PoCs published by Suraj Bhosale.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Online Ordering System 1.0, allowing an attacker to upload a malicious PHP file and achieve remote code execution (RCE) by sending a crafted multipart/form-data POST request.
Description
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in Online Ordering System 1.0, allowing an attacker to upload a malicious PHP file and achieve remote code execution (RCE) by sending a crafted multipart/form-data POST request.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H