CVE-2021-47900
CRITICALGila CMS < 2.0.0 - Unauthenticated Remote Code Execution via User-Agent Header Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47900. PoCs published by Enesdex.
AI-analyzed exploit summary This exploit targets Gila CMS 2.0.0 by leveraging unauthenticated remote code execution via manipulated cookies and headers. It injects PHP code into the User-Agent header and uses a path traversal in the GSESSIONID cookie to trigger execution.
Description
Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system commands by sending crafted requests to the admin endpoint.
Exploits (1)
This exploit targets Gila CMS 2.0.0 by leveraging unauthenticated remote code execution via manipulated cookies and headers. It injects PHP code into the User-Agent header and uses a path traversal in the GSESSIONID cookie to trigger execution.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H