PT-2019-18076 · Dedecms · Dedecms

Publicado

2019-01-15

·

Atualizado

2021-07-21

·

CVE-2019-6289

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS version V57 UTF8 SP2
Description The issue allows remote attackers to execute arbitrary PHP code by uploading a file with a safe file extension and then renaming it with a mixed-case variation of the .php extension. For example, using the filename 1.pHP.
Recommendations For DedeCMS version V57 UTF8 SP2, consider restricting file uploads to prevent the execution of arbitrary PHP code until a patch is available. As a temporary workaround, restrict access to the uploads/include/dialog/select soft.php file to minimize the risk of exploitation. Avoid allowing file renames with mixed-case variations of the .php extension in the affected upload functionality.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-6289

Produtos afetados

Dedecms