CVE-2020-28692: Malicious File Upload
Published Nov 16, 2020
·Updated
In Gila CMS 1.16.0, an attacker can upload a shell to tmp directy and abuse .htaccess through the logs function for executing PHP files.
Affected Software
1 affected component
GilaCMS Gila Cms=1.16.0
Event History
Nov 16, 2020
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
Description
Frequently Asked Questions
1
What is CVE-2020-28692?
CVE-2020-28692 is a vulnerability in Gila CMS 1.16.0, which allows an attacker to upload a shell to the tmp directory and abuse .htaccess through the logs function to execute PHP files.
2
How severe is CVE-2020-28692?
CVE-2020-28692 has a severity rating of 7.2, which is considered high.
3
How can an attacker exploit CVE-2020-28692?
An attacker can exploit CVE-2020-28692 by uploading a shell to the tmp directory and abusing .htaccess through the logs function to execute PHP files.
4
What is the affected software version?
The affected software version is Gila CMS 1.16.0.
5
Is there a workaround or fix for CVE-2020-28692?
To mitigate CVE-2020-28692, it is recommended to update to a patched version of Gila CMS or apply any available security patches provided by the vendor.