gist.github.com
https://gist.github.com/pak0s/ea7a80c2614d9cd43cfb8230c65c9fec CVE-2017-17098
CRITICAL
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
Record summary
CVE-2017-17098 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBgps-server.net GPS Tracking Software < 3.1 - Multiple VulnerabilitiesExploitDB exploitby Noman RiffatNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-17098 s1.gps-server.net
https://s1.gps-server.net/changelog.txt 43431exploit
https://www.exploit-db.com/exploits/43431