Revenue Collection System 1.0 SQL Injection / Remote Code Execution
Posted by deepcore on November 17, 2022 – 2:01 pm
Revenue Collection System version 1.0 suffers from an unauthenticated SQL injection vulnerability in step1.php that allows remote attackers to write a malicious PHP file to disk. The resulting file can then be accessed within the /rates/admin/DBbackup directory. This script will write the malicious PHP file to disk, issue a user-defined command, then retrieve the result of that command.
Post a reply
You must be logged in to post a comment.