Exploitation Summary
EIP tracks 4 public exploits for CVE-2017-9101.
PoCs published by Metasploit, Touhid M.Shaikh, jasperla, including Metasploit module exploits/multi/http/playsms_uploadcsv_exec.
AI-analyzed exploit summary This Metasploit module exploits an authenticated file upload vulnerability in PlaySMS 1.4 via the Phonebook import feature. It uploads a malicious CSV file containing PHP code in the User-Agent header, leading to remote code execution.
Description
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.
Exploits (4)
This Metasploit module exploits an authenticated file upload vulnerability in PlaySMS 1.4 via the Phonebook import feature. It uploads a malicious CSV file containing PHP code in the User-Agent header, leading to remote code execution.
This exploit leverages a file upload vulnerability in PlaySMS 1.4's phonebook import feature to achieve remote code execution. The attacker uploads a malicious CSV file containing PHP code in the 'Name' field, which is executed when the file is processed due to improper handling of user-supplied input.
This is a functional exploit for CVE-2017-9101, targeting PlaySMS 1.4. It leverages an authenticated RCE vulnerability via CSV upload in the phonebook feature, embedding PHP code in the User-Agent header to execute arbitrary commands.
This Metasploit module exploits an authenticated file upload vulnerability in PlaySMS 1.4 via the Phonebook import feature. It uploads a malicious CSV file containing PHP code in the User-Agent header, leading to remote code execution.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H