References https://avd.aliyun.com/detail?id=AVD-2018-9174 https://ultramangaia.github.io/blog/2018/DedeCMS5-7%E5%90%8E%E5%8F%B0%E4%B8%A4%E5%A4%84Getshell%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90.html https://stack.chaitin.com/vuldb/detail/e56bc001-ecdb-459c-9495-9222241381a6 https://www.cnblogs.com/AtesetEnginner/p/12088365.html https://www.venustech.com.cn/new_type/mzsjgg/20211210/23312.html https://blog.csdn.net/weixin_33921089/article/details/93246790 https://nvd.nist.gov/vuln/detail/CVE-2018-9174 https://github.com/advisories/GHSA-rg3v-469f-2gxq
Related VulnerabilitiesPoCCVE-2024-57241: DedeCMS - Open Redirect via download.phpPoC(CVE-2025-15004)DedeCMS至5.7.118版本freelist_main.php文件orderby参数SQL注入漏洞PoCCVE-2017-17731: DedeCMS 5.7 - SQL InjectionPoCCVE-2018-18608: DedeCMS 5.7 SP2 - Cross-Site ScriptingPoCCVE-2018-6910: DedeCMS 5.7 - Path DisclosurePoCCVE-2018-7700: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code ExecutionPoCCVE-2023-2059: DedeCMS 5.7.87 - Directory TraversalPoCCVE-2023-3578: DedeCMS 5.7.109 - Server-Side Request ForgeryPoCCVE-2023-49494: DedeCMS v5.7.111 - Cross-Site ScriptingPoCCVE-2018-6910: DedeCMS 5.7 Web Path DisclosurePoCCVE-2018-7700: Dedecms V5.7 后台任意代码执行PoCdedecms-carbuyaction-fileinclude: DedeCmsV5.6 Carbuyaction Fileinclude