DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/kongxin520/DedeCMS/blob/master/DedeCMS_5.7_Bug.md | Broken Link Third Party Advisory | 
| https://kongxin.gitbook.io/dedecms-5-7-bug/ | Exploit Third Party Advisory | 
| https://github.com/kongxin520/DedeCMS/blob/master/DedeCMS_5.7_Bug.md | Broken Link Third Party Advisory | 
| https://kongxin.gitbook.io/dedecms-5-7-bug/ | Exploit Third Party Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2018-02-13 21:29
Updated : 2024-11-21 04:11
NVD link : CVE-2018-6910
Mitre link : CVE-2018-6910
CVE.ORG link : CVE-2018-6910
JSON object : View
Products Affected
                dedecms
- dedecms
CWE
                
                    
                        
                        CWE-668
                        
            Exposure of Resource to Wrong Sphere
