mamaquieroserpentester.blogspot.com
http://mamaquieroserpentester.blogspot.com/2018/09/multiple-vulnerabilities-in-lg.html CVE-2018-16288
HIGHNuclei
LG SuperSign EZ CMS 2.5 - Local File Inclusion
Record summary
CVE-2018-16288 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBLG SuperSign EZ CMS 2.5 - Local File InclusionExploitDB exploitby Alejandro FanjulNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHLG SuperSign EZ CMS 2.5 - Local File InclusionCVSS 8.6
LG SuperSign CMS 2.5 allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs - aka local file inclusion.
Impact
An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.
Remediation
Apply the latest security patches or upgrade to a patched version of LG SuperSign EZ CMS.
WeaknessesCWE-200
Authorsdaffainfo
Template tagscvecve2018lfisupersignedblgvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CPE: cpe:2.3:a:lg:supersign_cms:2.5:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/45440 http://mamaquieroserpentester.blogspot.com/2018/09/multiple-vulnerabilities-in-lg.html https://nvd.nist.gov/vuln/detail/CVE-2018-16288 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-16288 45440exploit
https://www.exploit-db.com/exploits/45440