RULE(RULE ID:323780)

Rule General Information
Release Date: 2019-11-28
Rule Name: PlaySMS sendfromfile.php Authenticated Filename Field Code Execution Vulnerability (CVE-2017-9080)
Severity:
CVE ID:
Rule Protection Details
Description: PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: ExploitDB:42003
http://touhidshaikh.com/blog/poc/playsms-v1-4-rce/
ExploitDB:44599
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://playsms.org/