CVE-2019-8933 Information
Feb 14, 2021
cve
Description
In DedeCMS 5.7SP2 attackers can upload a .php file to the uploads/ directory (without being blocked by the Web Application Firewall) and then execute this file via this sequence of steps: visiting the management page clicking on the template clicking on Default Template Management clicking on New Template and modifying the filename from ../index.html to ../index.php.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://blog.csdn.net/qq_36093477/article/details/86681178
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: