Unrestricted File Upload at Logaritmo CRM Call Manager (Aware)
Aware Call Manager is a system developed by Logaritmo, a chilean based company.
After some unumeration I've reached a PHP script that allows me to upload a CSV file, and with a routinary bypass as changing the Content-Type to text/csv of a PHP custom script, I was able to upload a simple php web shell.
And as I've enumerated later, I've know the place where my file was stored /supervisor/csv/filename


I'll be updating this post soon..
Comentarios
Publicar un comentario