CVE-2018-9175: Code Injection
Published Apr 2, 2018
·Updated
DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselectmain.php because code within the database is accessible to uploads/dede/syscacheup.php.
Affected Software
1 affected component
DedeCMS Dedecms=5.7
Event History
Apr 2, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9175?
CVE-2018-9175 is considered a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2018-9175?
The recommended way to fix CVE-2018-9175 is to upgrade to a patched version of DedeCMS, as the vulnerability exists in version 5.7.
3
Who is affected by CVE-2018-9175?
Users of DedeCMS version 5.7 are primarily affected by CVE-2018-9175.
4
What type of attack can be executed via CVE-2018-9175?
CVE-2018-9175 allows remote attackers to execute arbitrary PHP code through manipulation of the egroup parameter.
5
Can CVE-2018-9175 lead to data breaches?
Yes, CVE-2018-9175 can potentially lead to data breaches due to the execution of arbitrary code on the server.