PHP-Fusion < 9.03.00...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

## CVE-2019-12099 11 May, 2019 • EXPLOIT Vendor fixed this vulnerability. Check Uploaded Files MIME types is assigned by default setting. Also will place a custom control in the new version for the avatar upload area. I would like to thank Frederick for his tolerant approach and his love for open source codes :)(github /FrederickChan) [>> Click for details <<](https://github.com/php-fusion/PHP-Fusion/commit/943432028b9e674433bb3f2a128b2477134110e6) [Exploit-DB Link](https://www.exploit-db.com/exploits/46839) [CVE-Mitre Link](https://nvd.nist.gov/vuln/detail/CVE-2019-12099) [Download php_fusion_profile_rce.rb](https://pentest.com.tr/exploits/php_fusion_profile_rce.rb) ## PHP-Fusion < 9.03.00 - RCE ``` ## # This module requires Metasploit: https://metasploit.com/download # Current source: https://github.com/rapid7/metasploit-framework ## class MetasploitModule < Msf::Exploit::Remote Rank = ExcellentRanking include Msf::Exploit::Remote::HttpClient def initialize(info = {})...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息