This exploit demonstrates an arbitrary file upload vulnerability in SIM-PKH 2.4.1, allowing attackers to upload malicious PHP files via a POST request to the admin module. The uploaded file is accessible at a predictable path, leading to remote code execution.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:SIM-PKH 2.4.1
Auth required
Prerequisites:Access to the admin panel · Valid PHP session cookie