vendor:
                    GPS Tracking Software
                by:
                    Noman Riffat
                9.8
                        CVSS
                    CRITICAL
                    Remote Code Injection, Remote File Inclusion
                    94
                        CWE
                    Product Name: GPS Tracking Software
                    Affected Version From:  <=3.0
                    Affected Version To:  <=3.0
                    Patch Exists: YES
                    Related CWE: CVE-2017-17097, CVE-2017-17098
                    CPE:  a:gps-server.net:gps_tracking_software
                    
							Metasploit: 
							N/A
						
                    
							Other Scripts: 
							N/A						
                    Platforms Tested:  Linux, Windows
                    2017
                    GPS-SERVER.NET SAAS CMS <=3.0 Multiple Vulnerabilities
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing. Login, signup and other common incidents are logged into a PHP file in /logs/ directory with the given input. The vulnerable parameter is "page" which is used to include files from /pages/ directory. The parameter is not sanitized and can be used to include remote files.
Mitigation:
					Upgrade to the latest version of GPS-SERVER.NET SAAS CMS