Payday
Enumeration
Default credentials - admin:admin
CS-Cart 1.3.3 - authenticated RCE
https://www.exploit-db.com/exploits/48891
get PHP shells from http://pentestmonkey.net/tools/web-shells/php-reverse-shell
edit IP && PORT
Upload to file manager change the extension from .php to .phtml
visit http://[victim]/skins/shell.phtml --> Profit. ...!
Initial Access
Visited and got reverse shell - https://192.168.117.39/skins/shell.phtml
PrivEsc
Brute force with rockyou or try simple thinking :)
patrick:patrick
Last updated