An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.sourcecodester.com/php/14374/online-bike-rental-phpmysql.html | product |
https://packetstormsecurity.com/files/158704/Online-Bike-Rental-1.0-Shell-Upload.html | vdb entry third party advisory |