Voting System 1.0 - Remote Code Execution (Unauthenticated)

Payload

*Remember to add a blank line after the php code. Change host, origin, referer to target machine IP. Copy the below payload in Burpsuite /candidates.php and send to repeater.

Check in for shell.php in http://10.10.10.239/images

Last updated