Beveiligingsadvies

CVE-2020-18917

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-08-24 19:34:10
Laatst bijgewerkt 2024-08-04 14:08:30
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.