Record summary

CVE-2018-16288 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBLG SuperSign EZ CMS 2.5 - Local File InclusionExploitDB exploitby Alejandro FanjulNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHLG SuperSign EZ CMS 2.5 - Local File InclusionCVSS 8.6

LG SuperSign CMS 2.5 allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs - aka local file inclusion.

Impact

An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.

Remediation

Apply the latest security patches or upgrade to a patched version of LG SuperSign EZ CMS.

WeaknessesCWE-200
Authorsdaffainfo
Template tagscvecve2018lfisupersignedblgvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CPE: cpe:2.3:a:lg:supersign_cms:2.5:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3