CVE-2017-17976
CRITICALPerfex CRM 1.9.7 - Unrestricted File Upload and Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17976. PoCs published by Ahmad Mahfouz.
AI-analyzed exploit summary This exploit demonstrates an unrestricted file upload vulnerability in PerfexCRM 1.9.7 via a misconfigured elFinder plugin. It bypasses file extension restrictions by using .php5 and injects PHP code into the uploaded file, leading to remote code execution.
Description
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
Exploits (1)
This exploit demonstrates an unrestricted file upload vulnerability in PerfexCRM 1.9.7 via a misconfigured elFinder plugin. It bypasses file extension restrictions by using .php5 and injects PHP code into the uploaded file, leading to remote code execution.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H