CVE-2018-9247

CRITICAL

Gxlcms QY v1.0.0713 - SQL Injection via upsql Function

Title source: llm
STIX 2.1

Description

The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then using INTO OUTFILE with a .php filename.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
http://www.atksec.com/cve/GxlcmsQY-v1.0.0713-getshell/index.html

Scores

CVSS v3 9.8
EPSS 0.0158
EPSS Percentile 72.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
gxlcms/gxlcms_qy 1.0.0713
Published Apr 04, 2018
Tracked Since Feb 18, 2026