Vulnerability Description
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use of '|' instead of '/' as a directory separator, in conjunction with a ".." sequence.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gxlcms | Gxlcms Qy | 1.0.0713 |
Related Weaknesses (CWE)
References
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-DirectoryTraversal/index.htmlExploitThird Party Advisory
- http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-DirectoryTraversal/index.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-9851?
CVE-2018-9851 is a vulnerability with a CVSS score of 7.5 (HIGH). In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use of '|' instead of '/' ...
How severe is CVE-2018-9851?
CVE-2018-9851 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9851?
Check the references section above for vendor advisories and patch information. Affected products include: Gxlcms Gxlcms Qy.