ZeroHour

CVE-2018-9174

CVSS 3.0
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.

Vendors
dedecms
Products
dedecms
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.