Record summary

CVE-2017-17098 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBgps-server.net GPS Tracking Software < 3.1 - Multiple VulnerabilitiesExploitDB exploitby Noman RiffatNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

4