============================================================================================================================================= | # Title : Backdrop CMS 1.27.1 PHP COde Injection Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 136.0.0 (64 bits) | | # Vendor : https://github.com/backdrop/backdrop/releases/download/1.27.1/backdrop.zip | ============================================================================================================================================= POC : [+] Dorking İn Google Or Other Search Enggine. [+] Code Description: Backdrop CMS 1.27.1 - Remote Command Execution Exploit in PHP (Related : https://packetstorm.news/files/id/178631/ Related CVE numbers: ) . [+] save code as poc.php. [+] Usage: php script.php [url] [+] PayLoad :