CVE-2018-6881: Infoleak
Published Feb 12, 2018
·Updated
EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
Affected Software
4 affected components
DedeCMS Dedecms=5.7
Phome Empirecms=6.6
Phome Empirecms=7.0
Phome Empirecms=7.2
Event History
Feb 12, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-6881?
CVE-2018-6881 is considered a high severity vulnerability due to its potential for exposing sensitive directory path information.
2
How does CVE-2018-6881 affect EmpireCMS and Dedecms?
CVE-2018-6881 allows remote attackers to discover the full path of the server on vulnerable versions of EmpireCMS and Dedecms.
3
What versions of EmpireCMS are vulnerable to CVE-2018-6881?
The vulnerable versions of EmpireCMS include 6.6, 7.0, and 7.2.
4
How do I mitigate CVE-2018-6881?
To mitigate CVE-2018-6881, ensure that you are using an updated version of EmpireCMS or Dedecms that has addressed this vulnerability.
5
Is CVE-2018-6881 a remote code execution vulnerability?
No, CVE-2018-6881 is not a remote code execution vulnerability but rather a path disclosure vulnerability.