Vulnerability Description
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dedecms | Dedecms | 5.7 |
Related Weaknesses (CWE)
References
- https://github.com/kongxin520/DedeCMS/blob/master/DedeCMS_5.7_Bug.mdBroken LinkThird Party Advisory
- https://kongxin.gitbook.io/dedecms-5-7-bug/ExploitThird Party Advisory
- https://github.com/kongxin520/DedeCMS/blob/master/DedeCMS_5.7_Bug.mdBroken LinkThird Party Advisory
- https://kongxin.gitbook.io/dedecms-5-7-bug/ExploitThird Party Advisory
FAQ
What is CVE-2018-6910?
CVE-2018-6910 is a vulnerability with a CVSS score of 7.5 (HIGH). DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
How severe is CVE-2018-6910?
CVE-2018-6910 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-6910?
Check the references section above for vendor advisories and patch information. Affected products include: Dedecms Dedecms.