First published: Thu Dec 13 2018(Updated: )
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by the filename=1.jpg.p*hp value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =5.7-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20129 is rated as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2018-20129, update DedeCMS to the latest version that addresses this vulnerability.
CVE-2018-20129 is a remote code execution vulnerability caused by improper handling of file uploads.
DedeCMS version 5.7 SP2 users are affected by CVE-2018-20129.
Yes, CVE-2018-20129 can be exploited remotely by attackers to execute arbitrary PHP code.