Main
Vulnerability Database
Exploits
ID:4998 - Exploit for Arbitrary file upload in PlaySMS - CVE-2017-9101
ID:4998 - Exploit for Arbitrary file upload in PlaySMS - CVE-2017-9101
Published: January 6, 2021
Vulnerability identifier: #VU38965
Vulnerability risk: Medium
CVE-ID: CVE-2017-9101
CWE-ID: CWE-434
Exploitation vector: Remote access
Vulnerable software:
PlaySMS
PlaySMS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote authenticated user to execute arbitrary code.
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.
Remediation
Install update from vendor's website.