sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.
References
Link | Resource |
---|---|
https://xz.aliyun.com/t/2237 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-04-02 03:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-9174
Mitre link : CVE-2018-9174
CVE.ORG link : CVE-2018-9174
JSON object : View
Products Affected
dedecms
- dedecms
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')