漏洞描述 【漏洞对象】DedeCMS 5.7 sp1 【涉及版本】DeDeCMS < 5.7-sp1,5.7sp1 【漏洞描述】该漏洞在/install/index.php(index.php.bak)文件中,漏洞起因是$$符号使用不当,导致变量覆盖,以至于最后引起远程文件包含漏洞。
相关漏洞推荐 POC CVE-2017-17731: DedeCMS 5.7 - SQL Injection POC CVE-2018-18608: DedeCMS 5.7 SP2 - Cross-Site Scripting POC CVE-2018-6910: DedeCMS 5.7 - Path Disclosure POC CVE-2018-7700: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution POC CVE-2023-2059: DedeCMS 5.7.87 - Directory Traversal POC CVE-2023-3578: DedeCMS 5.7.109 - Server-Side Request Forgery POC CVE-2023-49494: DedeCMS v5.7.111 - Cross-Site Scripting POC CVE-2017-17731: DedeCMS 5.7 - SQL Injection POC CVE-2018-6910: DedeCMS 5.7 Web Path Disclosure POC CVE-2018-7700: Dedecms V5.7 后台任意代码执行 POC dedecms-carbuyaction-fileinclude: DedeCmsV5.6 Carbuyaction Fileinclude POC dedecms-common-func-rce: DedeCMS common.func.php 远程命令执行漏洞 POC dedecms-config-xss: DedeCMS 5.7 - Cross-Site Scripting