Sploitus

Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp Cutenews

githubexploit · 2020-10-30

Exploit Code

README11 lines
## https://sploitus.com/exploit?id=CFF58BB0-D0E3-5E2E-BB07-20B2D6D212E4
# CVE-2019-11447-EXP
CuteNews Avatar  2.1.2 Remote Code Execution Vulnerability

Before run the python script, run the nc command firstly. The default port is 1234.

Then execute exploit.py, follow the tips and input required contents.

![image](https://github.com/khuntor/CVE-2019-11447-EXP/blob/main/img/1.jpg)

![image](https://github.com/khuntor/CVE-2019-11447-EXP/blob/main/img/2.png)