vendor:
Gila
by:
Enesdex
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Gila
Affected Version From: x < 2.0.0
Affected Version To: 2.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:gilacms:gila:2.0.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2021
Gila CMS 2.0.0 – Remote Code Execution (Unauthenticated)
Gila CMS version 2.0.0 and below is vulnerable to Remote Code Execution. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request with a malicious User-Agent header. The malicious payload will be executed on the server and the attacker can gain access to the server.
Mitigation:
Upgrade to the latest version of Gila CMS.