CVE-2017-9080
N/A
N/A
Summary
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://www.exploit-db.com/exploits/42003/
- https://www.exploit-db.com/exploits/44599/
- http://touhidshaikh.com/blog/poc/playsms-v1-4-rce/
References
- https://www.exploit-db.com/exploits/42003/
- https://www.exploit-db.com/exploits/44599/
- http://touhidshaikh.com/blog/poc/playsms-v1-4-rce/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.