Home > CVE > CVE-2018-20634-PHP Scripts Mall Advance B2B Script 2.1.4- allows remote attackers to cause a denial of service

CVE-2018-20634-PHP Scripts Mall Advance B2B Script 2.1.4- allows remote attackers to cause a denial of service

CVE-2018-20634-vikas-chaudhary

********************************************
# Exploit Title: PHP Scripts Mall Advance B2B Script 2.1.4- allows remote attackers to cause a denial of service (changed Page structure) via JavaScript code in the First Name field. (Bufferoverflow)
# Date: 30.12.2018
# Site Title : Entrepreneur B2B Script
# Vendor Homepage: https://www.phpscriptsmall.com/
# Software Link: http://198.38.86.159/~nced2bvda/index.php
# Category: Web Application
# Version: 2.1.4
# Exploit Author: Vikas Chaudhary
# Contact: https://www.facebook.com/profile.php?id=100011287630308
# Web: https://gkaim.com/
# Tested on: Windows 10 -Firefox
# CVE-2018-20634.

********************************************
# VENDOR SUMMARY :- PHP Scripts Mall Pvt. Ltd. is a professional software selling portal offering wide range of innovative.
PHP Scripts Mall is a leading business and technology firm with 12 years of successful track record
in completion and implementation of numerous projects in various verticals and domains..
It has 300 plus PHP scripts ready to buy.

# DESCRIPTION :- A Buffer Overflow, or buffer overrun, is a common software coding mistake that an attacker
could exploit to gain access to your system. Buffer overflow Vulnerability is found in Specified Vendor
By uploading these types of malicious code an attacker can change or redirect the admin
or guest user to any infectious link or also can harm the full site by changing site interface .
********************************************
Proof of Concept:-
————————–
1- Go to Site (http://198.38.86.159/~nced2bvda/index.php)
2- Click on => Register => and then fill the Form using your mail id ,
3-Now fill the Captcha and click on submit
4-Goto your mail and Verify it.
5-Now come back to site and Sign in using your Verified mail and Password.
6- Go to Profile =>Edit Profile and Put this Script in First Name


and click on Update
7- You will See that your Page structure will Change and again when you refresh it everything will be lost.
************************************************

Admin
Welcome Sir, .. Myself Vikas Chaudhary , i was interested in general knowledge since childhood , so i thought why not to share my knowledge with you, that's why i created this educational blog. Here you find world wide general knowledge of all Latest technology , Science & History Que , and Mysterious fact of the world. Here you also find knowledge about cyber security. Thanks for visit.. keep supporting....keep Loving
https://www.gkaim.com

Leave a Reply

%d bloggers like this: