Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-27747. PoCs published by Shubham Pandey, shubham-s-pandey.
AI-analyzed exploit summary This exploit demonstrates a file upload vulnerability in Petrol Pump Management Software v1.0, allowing arbitrary code execution by uploading a malicious PHP file via the profile.php component. The PoC includes steps to upload a phpinfo.php file, which is then accessible in the assets/images directory.
Description
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.
Exploits (2)
This exploit demonstrates a file upload vulnerability in Petrol Pump Management Software v1.0, allowing arbitrary code execution by uploading a malicious PHP file via the profile.php component. The PoC includes steps to upload a phpinfo.php file, which is then accessible in the assets/images directory.
The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-27747, describing attack vectors, affected components, and payloads for vulnerabilities such as XSS, SQL injection, and file upload RCE in Petrol Pump Management Software v1.0. No functional exploit code is provided, but the technical details are thorough and demonstrate a clear understanding of the vulnerabilities.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H