First published: Tue Feb 13 2018(Updated: )
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6910 is classified as a medium severity vulnerability due to its potential for information disclosure.
CVE-2018-6910 allows remote attackers to discover the full path of the installation through specific file requests.
To mitigate CVE-2018-6910, restrict access to sensitive files and implement proper security measures such as disabling directory listing.
Yes, CVE-2018-6910 can be easily exploited by attackers with knowledge of the file structure.
DedeCMS version 5.7 is specifically affected by CVE-2018-6910.