Code-Projects Online Hotel Reservation System Unrestricted File Upload Vulnerability
Vulnerability
A file upload vulnerability has been identified in Code-Projects Online Hotel Reservation System version 1.0. The issue resides in the file '/admin/addexec.php', where the 'image' argument is manipulated to allow unrestricted file uploads. This vulnerability can be exploited remotely, without any authentication or authorization.
Impact
Exploitation of this vulnerability allows for unauthorized file uploads, which could lead to remote code execution on the server.
Reproduction
To reproduce this vulnerability, send a POST request to '/admin/addexec.php' with the 'image' parameter. Include a file named 'shell.php' disguised as a PNG image. The server will accept the file, which can then be executed as a web shell.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
