Payday
Last updated
Last updated
Default credentials - admin:admin
CS-Cart 1.3.3 - authenticated RCE
get PHP shells from http://pentestmonkey.net/tools/web-shells/php-reverse-shell
edit IP && PORT
Upload to file manager change the extension from .php to .phtml
visit http://[victim]/skins/shell.phtml --> Profit. ...!
Visited and got reverse shell - https://192.168.117.39/skins/shell.phtml
Brute force with rockyou or try simple thinking :)
patrick:patrick