Code-Projects Online Hotel Reservation System Unrestricted File Upload Vulnerability

Vulnerability

A file upload vulnerability has been identified in Code-Projects Online Hotel Reservation System version 1.0. The issue resides in the file '/admin/addexec.php', where the 'image' argument is manipulated to allow unrestricted file uploads. This vulnerability can be exploited remotely, without any authentication or authorization.

Impact

Exploitation of this vulnerability allows for unauthorized file uploads, which could lead to remote code execution on the server.

Reproduction

To reproduce this vulnerability, send a POST request to '/admin/addexec.php' with the 'image' parameter. Include a file named 'shell.php' disguised as a PNG image. The server will accept the file, which can then be executed as a web shell.

Added: Oct 7, 2025, 5:18 AM
Updated: Oct 7, 2025, 5:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.7
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.