CVE-2024-57487
MEDIUMCar Rental System 1.0 File Upload RCE (Authenticated)
Title source: metasploitExploitation Summary
EIP tracks 2 public exploits for CVE-2024-57487.
PoCs published by aaryan-11-x, Aaryan Golatkar, including Metasploit module exploits/multi/http/carrental_fileupload_rce.
AI-analyzed exploit summary This repository provides a writeup for CVE-2024-57487, an authenticated remote code execution vulnerability in the Online Car Rental System v1.0 via file upload, and CVE-2024-57488, an authenticated stored XSS vulnerability. No exploit code is included.
Description
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.
Exploits (2)
This repository provides a writeup for CVE-2024-57487, an authenticated remote code execution vulnerability in the Online Car Rental System v1.0 via file upload, and CVE-2024-57488, an authenticated stored XSS vulnerability. No exploit code is included.
This Metasploit module exploits an authenticated file upload vulnerability in Online Car Rental System 1.0, allowing remote code execution via malicious PHP script upload through the `changeimage1.php` endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N