Critical severity9.8NVD Advisory· Published Jan 2, 2018· Updated Jun 17, 2026
CVE-2017-17098
CVE-2017-17098
Description
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=3.0
Patches
Vulnerability mechanics
References
3- gist.github.com/pak0s/ea7a80c2614d9cd43cfb8230c65c9fecnvdPatchThird Party Advisory
- www.exploit-db.com/exploits/43431/nvdExploitThird Party AdvisoryVDB Entry
- s1.gps-server.net/changelog.txtnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.