Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Gila CMS < 2.0.0 - Remote Code Execution
Vulnerability Description
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
PHP程序中Include/Require语句包含文件控制不恰当(PHP远程文件包含)
Vulnerability Title
Gila CMS 安全漏洞
Vulnerability Description
Gila CMS是Gila CMS公司的一套基于PHP和MySQL的开源内容管理系统(CMS)。 Gila CMS 2.0.0之前版本存在安全漏洞,该漏洞源于未经验证的HTTP标头,可能导致未经身份验证的攻击者执行任意系统命令。
CVSS Information
N/A
Vulnerability Type
N/A