CVE-2018-12046: Input Validation
Published Jun 8, 2018
·Updated
DedeCMS through 5.7SP2 allows arbitrary file write in dede/filemanagecontrol.php via a dede/filemanageview.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.
Affected Software
4 affected components
DedeCMS Dedecms<5.7
DedeCMS Dedecms=5.7
DedeCMS Dedecms=5.7-sp1
DedeCMS Dedecms=5.7-sp2
Event History
Jun 8, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12046?
CVE-2018-12046 is classified as a critical vulnerability due to its potential for arbitrary file writing.
2
How do I fix CVE-2018-12046?
To fix CVE-2018-12046, it is recommended to upgrade DedeCMS to a version later than 5.7SP2.
3
What type of vulnerability is CVE-2018-12046?
CVE-2018-12046 is an arbitrary file write vulnerability in DedeCMS.
4
What versions of DedeCMS are affected by CVE-2018-12046?
CVE-2018-12046 affects DedeCMS versions up to and including 5.7SP2.
5
Can CVE-2018-12046 be exploited remotely?
Yes, CVE-2018-12046 can be exploited remotely if an attacker sends a crafted request.