Vulnerabilities
Vulnerable Software
Gilacms:  >> Gila Cms  >> 1.10.6  Security Vulnerabilities
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
CVSS Score
3.8
EPSS Score
0.003
Published
2024-01-02
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
CVSS Score
3.8
EPSS Score
0.003
Published
2024-01-02
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
CVSS Score
3.8
EPSS Score
0.003
Published
2024-01-02
Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin account.
CVSS Score
8.8
EPSS Score
0.002
Published
2020-05-21
Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_preview_theme.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-05-21
Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a related issue to CVE-2019-9647.
CVSS Score
9.3
EPSS Score
0.003
Published
2019-10-13
Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/controllers/fm.php. The attacker needs to use admin/media_upload and fm/move.
CVSS Score
9.9
EPSS Score
0.004
Published
2019-10-13
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
CVSS Score
4.9
EPSS Score
0.025
Published
2019-09-21


Contact Us

Shodan ® - All rights reserved