nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-16123 CVE-2019-16123
HIGHNuclei
PilusCart 1.4.1 - Local File Disclosure
Record summary
CVE-2019-16123 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBPilusCart 1.4.1 - Local File DisclosureExploitDB exploitby Damian EbeltiesNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHPilusCart <=1.4.1 - Local File InclusionCVSS 7.5
PilusCart versions 1.4.1 and prior suffer from a file disclosure vulnerability via local file inclusion.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and remote code execution.
Remediation
Upgrade to a patched version of PilusCart (>=1.4.2) or apply the vendor-supplied patch to mitigate the LFI vulnerability.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2019piluscartlfipacketstormedbkartatopiavuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:kartatopia:piluscart:*:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/154250/PilusCart-1.4.1-Local-File-Disclosure.html https://www.exploit-db.com/exploits/47315 https://nvd.nist.gov/vuln/detail/CVE-2019-1653 https://zerodays.lol/ https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3exploit-db.com
https://www.exploit-db.com/exploits/47315 zerodays.lol
https://zerodays.lol/