CVE-2019-6289: High severity dedecms v6 vulnerability
Published Jan 15, 2019
·Updated
uploads/include/dialog/selectsoft.php in DedeCMS V57UTF8SP2 allows remote attackers to execute arbitrary PHP code by uploading with a safe file extension and then renaming with a mixed-case variation of the .php extension, as demonstrated by the 1.pHP filename.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Jan 15, 2019
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-6289?
CVE-2019-6289 has a severity rating of high due to its ability to allow remote code execution.
2
How do I fix CVE-2019-6289?
To fix CVE-2019-6289, upgrade DedeCMS to the latest version that addresses this vulnerability.
3
What types of attacks can be executed with CVE-2019-6289?
CVE-2019-6289 allows attackers to execute arbitrary PHP code by exploiting file upload and renaming techniques.
4
Which versions of DedeCMS are affected by CVE-2019-6289?
CVE-2019-6289 affects DedeCMS version 5.7 SP2.
5
Can CVE-2019-6289 be mitigated?
Mitigation strategies for CVE-2019-6289 include implementing stricter file upload controls and validating file types.