Vulnerability Details CVE-2018-12046
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-12046
-
cpe:2.3:a:dedecms:dedecms:-
-
cpe:2.3:a:dedecms:dedecms:5.5
-
cpe:2.3:a:dedecms:dedecms:5.6
-
cpe:2.3:a:dedecms:dedecms:5.7