CVE-2018-16784: High severity dedecms v6 vulnerability
Published Sep 21, 2018
·Updated
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Sep 21, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16784?
CVE-2018-16784 has a high severity level due to its potential for remote code execution.
2
What vulnerability does CVE-2018-16784 exploit?
CVE-2018-16784 exploits XML injection vulnerabilities in DedeCMS 5.7 SP2.
3
How do I fix CVE-2018-16784?
To fix CVE-2018-16784, upgrade DedeCMS to a version that addresses the XML injection vulnerabilities.
4
What software versions are affected by CVE-2018-16784?
CVE-2018-16784 affects DedeCMS version 5.7 SP2.
5
What are the consequences of CVE-2018-16784 if exploited?
If exploited, CVE-2018-16784 can lead to remote code execution on the affected system.