Active eCommerce CMS By ActiveITzone 23471405

Active eCommerce CMS By ActiveITzone 23471405 v9.8.1

No permission to download

Chijioke

Member
Apr 18, 2020
58
9
8
@NullMaster
guys any idea how to get .svg extension activate on the file uploader on Ver.4.0 /

when uploading the below error comes ,

also on my server the mysql was automatically deleted .. may they have a back door if someone can help with that would save us all , because i was doing modifications, but suddenly database was gone and http 500 error comes , :cry::cry::cry::cry::cry::cry:,

thanks in advance ,
@nulled123, @phpcore @TassieNZ
Please could you help solve the automatic erasure of the mysql in v4.0.
Thanks in advance
 
Last edited:
  • Like
Reactions: wonraywildsparks
Apr 30, 2020
55
72
18
I believe the backdoor that drops the entire database is in the /vendor/laracon21/timezones/src/routes/web.php

All of laracon21 packages are backdoors. Nothing usefull there.

Found backdoors in mehedi-iitdu/core-component-repository too.

This ZIP file contains all modifications I made in those files. It may work, I'm not sure yet. But if you want to try, just unzip the file inside vendor directory.

I recommend you to change the database password as well.

EDIT: Forgot one file: /app/Http/Controllers/DemoController.php, comment the lines 42 and 43.
 

Attachments

  • ActiveEcommerce_BackdoorSolution.zip
    102.9 KB · Views: 49
  • Love
Reactions: Chijioke

Chijioke

Member
Apr 18, 2020
58
9
8
I believe the backdoor that drops the entire database is in the /vendor/laracon21/timezones/src/routes/web.php

All of laracon21 packages are backdoors. Nothing usefull there.

Found backdoors in mehedi-iitdu/core-component-repository too.

This ZIP file contains all modifications I made in those files. It may work, I'm not sure yet. But if you want to try, just unzip the file inside vendor directory.

I recommend you to change the database password as well.

EDIT: Forgot one file: /app/Http/Controllers/DemoController.php, comment the lines 42 and 43.

Thanks so much. Would try!
 
  • Love
Reactions: kasun955

raqib

Active member
Jan 22, 2020
138
43
28
Screenshot 2021-03-03 181350.png
after some time my database blank, Killer Script 💀 ☠️ 😀
i just added some addon
 

raqib

Active member
Jan 22, 2020
138
43
28
I believe the backdoor that drops the entire database is in the /vendor/laracon21/timezones/src/routes/web.php

All of laracon21 packages are backdoors. Nothing usefull there.

Found backdoors in mehedi-iitdu/core-component-repository too.

This ZIP file contains all modifications I made in those files. It may work, I'm not sure yet. But if you want to try, just unzip the file inside vendor directory.

I recommend you to change the database password as well.

EDIT: Forgot one file: /app/Http/Controllers/DemoController.php, comment the lines 42 and 43.
can I report this to Envato? I have purchased this item
 
Apr 30, 2020
55
72
18
can I report this to Envato? I have purchased this item

It's complicated. In theory yes. Envato prohibits any type of backdoor in its products. But if backdoors are not active when using the software legitimately, it is difficult to explain how you found the backdoor.

But the code that deletes the entire database is very explicit, I think it can be reported.
 
  • Like
Reactions: Chijioke

raqib

Active member
Jan 22, 2020
138
43
28
It's complicated. In theory yes. Envato prohibits any type of backdoor in its products. But if backdoors are not active when using the software legitimately, it is difficult to explain how you found the backdoor.

But the code that deletes the entire database is very explicit, I think it can be reported.
Reported
 
Apr 30, 2020
55
72
18
Yes, seems like it.
User has no privacy for his business - not a good decision

The backdoor that drops the database has been inserted into the routes. This opens a security vulnerability. If a malicious agent accesses that particular route in a store's system using Active eCommerce, even if the software was legitimate, it would trigger the behavior of the backdoor, erasing all data from the database.
 
  • Wow
Reactions: Chijioke and raqib

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu