CVE-2018-16287: Malicious File Upload
Published Sep 14, 2018
·Updated
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
Affected Software
1 affected component
LG SuperSign CMS
Event History
Sep 14, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-16287.
2
What is the severity of CVE-2018-16287?
The severity of CVE-2018-16287 is critical with a score of 9.8.
3
What software is affected by CVE-2018-16287?
LG SuperSign CMS is affected by CVE-2018-16287.
4
How does CVE-2018-16287 exploit the vulnerability?
CVE-2018-16287 allows file upload via the signEzUI/playlist/edit/upload/..%2f URIs.
5
Is there any reference material available for CVE-2018-16287?
Yes, you can find more information about CVE-2018-16287 at http://mamaquieroserpentester.blogspot.com/2018/09/multiple-vulnerabilities-in-lg.html.