CVE-2017-9080
19.05.2017, 15:29
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.Enginsight
Vendor | Product | Version |
---|---|---|
playsms | playsms | 1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration