============================================================================================================================================= | # Title : B2B Hospitality Travel CMS 1.11 Remote File Upload Vulnerability | | # Author : indoushka | | # Tested on : windows 11 Fr(Pro) / browser : Mozilla firefox 137.0.1 (64 bits) | | # Vendor : https://www.b2bhospitalityindia.com/ | ============================================================================================================================================= POC : [+] Dorking İn Google Or Other Search Enggine. [+] The following html code uploads a executable malicious file remotely . [+] Save code As : poc.html [+] Line 09 set your Target [+] Link to the uploaded files :/uopload/evil.php [+] use payload : Career Vacancy Form


















Greetings to :===================================================================================== jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)| ============================================================