Exploitation Summary
EIP tracks 2 public exploits for CVE-2019-9581. PoCs published by 0sunday, AkkuS.
AI-analyzed exploit summary This exploit targets CVE-2019-9581 in Booked Scheduler 2.7.5, allowing authenticated remote command execution via a malicious file upload in the theme management functionality. The PoC uploads a PHP shell disguised as a favicon and provides interactive command execution.
Description
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitrary Web/custom-favicon.php PHP code, because Presenters/Admin/ManageThemePresenter.php does not ensure an image file extension.
Exploits (2)
This exploit targets CVE-2019-9581 in Booked Scheduler 2.7.5, allowing authenticated remote command execution via a malicious file upload in the theme management functionality. The PoC uploads a PHP shell disguised as a favicon and provides interactive command execution.
This Metasploit module exploits a file upload vulnerability in Booked Scheduler v2.7.5, allowing remote command execution by uploading a malicious PHP payload via the Favicon field in the 'Look and Feel' section.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H