'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2018-20129: DedeCMS V5.7 SP2 File Upload getshell Vulnerability
Severity:high
CVE ID:CVE-2018-20129
| Descripiton:
|
Desdev DedeCMS (Dream Weaving Content Management System) is a set of open source PHP website content management system (CMS) that integrates content publishing, editing, management and retrieval from China Zhuozhuo Network (Desdev) Technology Co., Ltd. There is a security vulnerability in the uploads/include/dialog/select_images_post.php file in Desdev DedeCMS version 5.7 SP2. A remote attacker could exploit this vulnerability to upload and execute arbitrary PHP code. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.