CVE-2020-18917
24.08.2021, 20:15
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Vendor | Product | Version |
---|---|---|
dedecms | dedecms | 5.7:sp2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration