CVE-2024-29410

Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)

STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-29410. PoCs published by Sandeep Vishwakarma, hackersroot.

AI-analyzed exploit summary This exploit demonstrates a file upload vulnerability in Petrol Pump Management Software v1.0, allowing arbitrary PHP code execution by uploading a malicious file via the 'Image' field in the admin panel. The PoC includes steps to upload a PHP file containing phpinfo() and confirms execution via a predictable path.

Description

Petrol Pump Management Software v1.0 - Remote Code Execution (RCE)

Exploits (2)

exploitdb WORKING POC
by Sandeep Vishwakarma · textwebappsphp
https://www.exploit-db.com/exploits/51943

This exploit demonstrates a file upload vulnerability in Petrol Pump Management Software v1.0, allowing arbitrary PHP code execution by uploading a malicious file via the 'Image' field in the admin panel. The PoC includes steps to upload a PHP file containing phpinfo() and confirms execution via a predictable path.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Petrol Pump Management Software v1.0
Auth required
Prerequisites: Access to admin panel · Default credentials ([email protected]:admin)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WRITEUP 1 stars
by hackersroot · poc
https://github.com/hackersroot/CVE-PoC/tree/main/CVE-2024-29410.md

The repository provides a detailed technical writeup for CVE-2024-29410, describing a file upload vulnerability in Petrol Pump Management Software v1.0 that leads to remote code execution. It includes step-by-step attack vectors and a proof-of-concept payload.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Petrol Pump Management Software v1.0
Auth required
Prerequisites: access to the admin panel · default credentials ([email protected]:admin)
devstral-2 · analyzed Feb 27, 2026 Full analysis →

Details

Status draft
Tracked Since Feb 18, 2026