Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://projectworlds.in/free-projects/php-projects/car-rental-project-in-php-and-mysql/ | product |
https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp | third party advisory exploit |
https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp/blob/master/CarRental-Unauth-RCE.py | third party advisory exploit |