Home > CVE > CVE-2018-20629- PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal Vulnerability

CVE-2018-20629- PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal Vulnerability

CVE-2018-20629-vikas-chaudhary

***************************************************
# Exploit Title: PHP Scripts Mall Charity Donation Script readymadeb2bscript has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
# Date: 30.12.2018
# Site Title: Charity Donation Script
# Vendor Homepage: https://www.phpscriptsmall.com/
# Software Link: https://www.phpscriptsmall.com/product/charity-donation-script/
# Category: Web Application
# Exploit Author: Vikas Chaudhary
# Contact: https://www.facebook.com/profile.php?id=100011287630308
# Web: https://gkaim.com/
# Tested on: Windows 10 -Firefox
# CVE-2018-20629.
************************************************
## VENDOR SUMMARY :- PHP Scripts Mall Pvt. Ltd. is a professional software selling portal offering wide range of innovative. PHP Scripts Mall is a leading business and technology firm with 12 years of successful track record in completion and implementation of numerous projects in various
verticals and domains.. It has 300 plus PHP scripts ready to buy.


## Vulnerability Description => A path traversal attack (also known as directory traversal) aims to access files and directories that are stored outside the web root folder. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on file system including application source code or configuration and critical system files.
**************************************************
Proof of Concept:-
————————–
1. Go to the site (https://www.phpscriptsmall.com/product/charity-foundation-script/ ) .
2. Select user demo
3-Open Burpsuit and intercept the data.
4-Now Pick any url contains wp-content ex (http://readymadeb2bscript.com/demo/charity-crowdfunding/uploads/payproof/pay_5be6685c768f9.png )
5- Now show response in browser and delete the last portion of url (after last / ) Ex- http://readymadeb2bscript.com/demo/charity-crowdfunding/uploads/
6- You will get all The file lists

** Also can check it by intruder .**
**************************************************

Admin
Welcome Sir, .. Myself Vikas Chaudhary , i was interested in general knowledge since childhood , so i thought why not to share my knowledge with you, that's why i created this educational blog. Here you find world wide general knowledge of all Latest technology , Science & History Que , and Mysterious fact of the world. Here you also find knowledge about cyber security. Thanks for visit.. keep supporting....keep Loving
https://www.gkaim.com

Leave a Reply

%d bloggers like this: