PT-2017-13798 · Gxlcms · Gxlcms

Published

2017-10-02

·

Updated

2019-10-03

·

CVE-2017-14979

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gxlcms (affected versions not specified)
Description The issue allows remote attackers to read arbitrary files via modified pathnames in the s parameter to "index.php". This is related to Lib/Admin/Action/TplAction.class.php and Lib/Admin/Common/function.php, where an unsafe character-replacement approach is used in an attempt to restrict access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-14979

Affected Products

Gxlcms