Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.
References
Link | Resource |
---|---|
https://infosecdb.wordpress.com/2020/01/05/gilacms-1-11-8-remote-code-execution/ | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-01-06T18:43:47
Updated: 2020-01-06T18:43:47
Reserved: 2020-01-05T00:00:00
Link: CVE-2020-5514
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-01-06T19:15:11.577
Modified: 2020-01-09T15:03:49.227
Link: CVE-2020-5514
JSON object: View
Redhat Information
No data.
CWE