File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://projectworlds.in/free-projects/php-projects/house-rental-and-property-listing-project-php-mysql/ | third party advisory exploit |
https://github.com/hyd3sec/HouseRental_Unauth_RCE/blob/master/HouseRentalRCE.py | third party advisory exploit |