Clinic's Patient Management System 1.0 - Unauthenticated RCE
zetlyn/cve-metasploit exploit cve CVE-2022-40471 known 2022-10-31
Properties
| platform | PHPreceipt
What the source handed over{
"aliases": [],
"arch": "php",
"author": [
"Aaryan Golatkar",
"Oğulcan Hami Gül"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits an unauthenticated file upload vulnerability in Clinic's\n Patient Management System 1.0. An attacker can upload a PHP web shell and execute\n it by leveraging directory listing enabled on the `/pms/user_images` directory.",
"disclosure_date": "2022-10-31",
"fullname": "exploit/multi/http/clinic_pms_fileupload_rce",
"is_install_path": true,
"mod_time": "2026-04-22 11:57:58 +0000",
"name": "Clinic's Patient Management System 1.0 - Unauthenticated RCE",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/clinic_pms_fileupload_rce.rb",
"platform": "PHP",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/clinic_pms_fileupload_rce",
"references": [
"EDB-51779",
"CVE-2022-40471",
"URL-https://www.cve.org/CVERecord?id=CVE-2022-40471",
"URL-https://drive.google.com/file/d/1m-wTfOL5gY3huaSEM3YPSf98qIrkl-TW/view"
],
"rport": 80,
"session_types": false,
"targets": [
"Clinic Patient Management System 1.0"
],
"type": "exploit"
} |
|---|---|
| rank | 600 Excellent. Cannot crash the service. A memory-corruption exploit does not qualify. receipt
What the source handed over{
"aliases": [],
"arch": "php",
"author": [
"Aaryan Golatkar",
"Oğulcan Hami Gül"
],
"autofilter_ports": [
80,
8080,
443,
8000,
8888,
8880,
8008,
3000,
8443
],
"autofilter_services": [
"http",
"https"
],
"check": true,
"default_credential": false,
"description": "This module exploits an unauthenticated file upload vulnerability in Clinic's\n Patient Management System 1.0. An attacker can upload a PHP web shell and execute\n it by leveraging directory listing enabled on the `/pms/user_images` directory.",
"disclosure_date": "2022-10-31",
"fullname": "exploit/multi/http/clinic_pms_fileupload_rce",
"is_install_path": true,
"mod_time": "2026-04-22 11:57:58 +0000",
"name": "Clinic's Patient Management System 1.0 - Unauthenticated RCE",
"needs_cleanup": true,
"notes": {
"Reliability": [
"repeatable-session"
],
"SideEffects": [
"artifacts-on-disk"
],
"Stability": [
"crash-safe"
]
},
"path": "/modules/exploits/multi/http/clinic_pms_fileupload_rce.rb",
"platform": "PHP",
"post_auth": false,
"rank": 600,
"ref_name": "multi/http/clinic_pms_fileupload_rce",
"references": [
"EDB-51779",
"CVE-2022-40471",
"URL-https://www.cve.org/CVERecord?id=CVE-2022-40471",
"URL-https://drive.google.com/file/d/1m-wTfOL5gY3huaSEM3YPSf98qIrkl-TW/view"
],
"rport": 80,
"session_types": false,
"targets": [
"Clinic Patient Management System 1.0"
],
"type": "exploit"
} |
Text
This module exploits an unauthenticated file upload vulnerability in Clinic's
Patient Management System 1.0. An attacker can upload a PHP web shell and execute
it by leveraging directory listing enabled on the `/pms/user_images` directory.