DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.
References
Link | Resource |
---|---|
https://xz.aliyun.com/t/2237 | Third Party Advisory |
https://xz.aliyun.com/t/2237 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://xz.aliyun.com/t/2237 - Third Party Advisory |
Information
Published : 2018-04-02 03:29
Updated : 2024-11-21 04:15
NVD link : CVE-2018-9175
Mitre link : CVE-2018-9175
CVE.ORG link : CVE-2018-9175
JSON object : View
Products Affected
dedecms
- dedecms
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')