4
CVSSv2

CVE-2019-16679

Published: 21/09/2019 Updated: 23/09/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Gila CMS prior to 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gilacms gila cms

Exploits

# Exploit Title: Authenticated Local File Inclusion(LFI) in GilaCMS # Google Dork: N/A # Date: 04-08-2019 # Exploit Author: Sainadh Jamalpur # Vendor Homepage: githubcom/GilaCMS/gila # Software Link: githubcom/GilaCMS/gila # Version: 1109 # Tested on: XAMPP version 322 in Windows 10 64bit, # CVE : CVE-2019-16679 *********** * ...
Gila CMS versions prior to 1111 suffer from a local file inclusion vulnerability ...