mirror of
https://github.com/0xMarcio/cve.git
synced 2026-04-12 05:08:32 +02:00
768 B
768 B
CVE-2017-9080
Description
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.
POC
Reference
- http://touhidshaikh.com/blog/poc/playsms-v1-4-rce/
- https://www.exploit-db.com/exploits/42003/
- https://www.exploit-db.com/exploits/44599/