Описание
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dedecms:dedecms:5.7:sp2:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.00909
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-178
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename.
EPSS
Процентиль: 75%
0.00909
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-178