Beveiligingsadvies

CVE-2018-9134

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-03-30 16:00:00
Laatst bijgewerkt 2024-08-05 07:17:51
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.