7.8
CVSSv2

CVE-2018-16288

Published: 14/09/2018 Updated: 07/11/2018
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.6 | Impact Score: 4 | Exploitability Score: 3.9
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lg supersign cms 2.5

Exploits

# Exploit Title: LG SuperSign EZ CMS 25 - Local File Inclusion # Date: 2018-09-13 # Exploit Author: Alejandro Fanjul # Vendor Homepage: wwwlgcom/ar/software-lg-supersign # Version: SuperSign EZ (CMS) # Tested on: Web OS 40 # CVE : CVE-2018-16288 # More info: mamaquieroserpentesterblogspotcom/2018/09/multiple-vulnerabilities-in ...
LG SuperSign EZ CMS version 25 suffers from a local file inclusion vulnerability ...