First published: Fri Sep 21 2018(Updated: )
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =5.7-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16784 has a high severity level due to its potential for remote code execution.
CVE-2018-16784 exploits XML injection vulnerabilities in DedeCMS 5.7 SP2.
To fix CVE-2018-16784, upgrade DedeCMS to a version that addresses the XML injection vulnerabilities.
CVE-2018-16784 affects DedeCMS version 5.7 SP2.
If exploited, CVE-2018-16784 can lead to remote code execution on the affected system.