Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2018-6910 โ€” AI Deep Analysis Summary

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: DedeCMS 5.7 suffers from an **Information Disclosure** vulnerability. ๐Ÿ“‰ **Consequences**: Attackers can retrieve the **full server file path** via direct requests to specific PHP files.

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: The flaw lies in **improper error handling** or path exposure in `include/downmix.inc.php` and `inc/inc_archives_functions.php`.โ€ฆ

Q3Who is affected? (Versions/Components)

๐ŸŽฏ **Affected**: **Desdev DedeCMS** (Zhimeng CMS). ๐Ÿ“ฆ **Version**: Specifically **Version 5.7**. ๐ŸŒ **Component**: The PHP CMS engine itself.

Q4What can hackers do? (Privileges/Data)

๐Ÿ•ต๏ธ **Hackers Can**: Send direct HTTP requests to trigger errors. ๐Ÿ’พ **Data Leaked**: **Full absolute file paths** on the server. ๐Ÿšซ **Note**: Data is limited to paths, not direct RCE or DB dump in this specific vector.

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: **LOW**. ๐Ÿšซ **Auth Required**: **None**. ๐ŸŒ **Remote**: Yes, any remote attacker can exploit this without login credentials.

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ’ฅ **Public Exp?**: **YES**. ๐Ÿ“œ **PoC**: Available via **Nuclei templates** (projectdiscovery) and GitHub repositories (kongxin520). ๐Ÿ”„ **Wild Exploitation**: High potential due to simplicity.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: Scan for direct requests to: 1. `/include/downmix.inc.php` 2. `/inc/inc_archives_functions.php`. ๐Ÿ‘€ **Indicator**: Look for **file path strings** in the HTTP response body.

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿฉน **Official Fix**: Data does **not** list a specific official patch version. ๐Ÿ“… **Published**: 2018-02-13. โš ๏ธ **Status**: Likely requires manual code modification or upgrading to a patched fork if available.

Q9What if no patch? (Workaround)

๐Ÿ›ก๏ธ **Workaround**: **Block access** to `downmix.inc.php` and `inc_archives_functions.php` via WAF or Web Server config (Nginx/Apache).โ€ฆ

Q10Is it urgent? (Priority Suggestion)

โšก **Urgency**: **MEDIUM-HIGH**. ๐Ÿ“‰ **Risk**: While it only leaks paths, this aids **further attacks** (like LFI or RCE). ๐Ÿƒ **Action**: Patch immediately if running DedeCMS 5.7.