> For the complete documentation index, see [llms.txt](https://kashz.gitbook.io/kashz-jewels/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kashz.gitbook.io/kashz-jewels/services/magento.md).

# magento

## Magento v1.9.0.0

```bash
https://www.exploit-db.com/exploits/37977

Catalog > Manage Products > Select a product > Edit > Custom Options > Add New Option
Input Type = File
Allowed File Extensions = .php
Save

Go to product page, select shell.php and add to cart > file is uploaded.

(Authenticated) https://www.exploit-db.com/exploits/37811
```
