vendor:
GPS Tracking Software
by:
Noman Riffat
9.8
CVSS
CRITICAL
Remote Code Injection, Remote File Inclusion
94
CWE
Product Name: GPS Tracking Software
Affected Version From: <=3.0
Affected Version To: <=3.0
Patch Exists: YES
Related CWE: CVE-2017-17097, CVE-2017-17098
CPE: a:gps-server.net:gps_tracking_software
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux, Windows
2017
GPS-SERVER.NET SAAS CMS <=3.0 Multiple Vulnerabilities
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing. Login, signup and other common incidents are logged into a PHP file in /logs/ directory with the given input. The vulnerable parameter is "page" which is used to include files from /pages/ directory. The parameter is not sanitized and can be used to include remote files.
Mitigation:
Upgrade to the latest version of GPS-SERVER.NET SAAS CMS