### [CVE-2020-5515](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5515) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection. ### POC #### Reference - http://packetstormsecurity.com/files/158114/Gila-CMS-1.11.8-SQL-Injection.html - http://packetstormsecurity.com/files/158114/Gila-CMS-1.11.8-SQL-Injection.html - http://packetstormsecurity.com/files/158140/Gila-CMS-1.1.18.1-SQL-Injection-Shell-Upload.html - http://packetstormsecurity.com/files/158140/Gila-CMS-1.1.18.1-SQL-Injection-Shell-Upload.html #### Github - https://github.com/0ps/pocassistdb - https://github.com/ARPSyndicate/cvemon - https://github.com/jweny/pocassistdb - https://github.com/superlink996/chunqiuyunjingbachang