Desdev DedeCMS(织梦内容管理系统)是中国卓卓网络(Desdev)公司的一套基于PHP的开源内容管理系统(CMS)。该系统具有内容发布、内容管理、内容编辑和内容检索等功能。 DedeCMS 5.7.106之前版本存在代码注入漏洞,该漏洞源于文件uploads/dede/article_allowurl_edit.php存在问题,对参数allurls的操作会导致代码注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | DedeCMS | 5.7.106 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | DedeCMS文件包含漏洞导致后台getshell(CVE-2023-2928)复现 | https://github.com/CN016/DedeCMS-getshell-CVE-2023-2928- | POC Details |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/DedeCMS%205.7%20file_manage_control.php%20%E6%96%87%E4%BB%B6%E5%8C%85%E5%90%AB%20RCE%20CVE-2023-2928.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-26128 | 8.4 HIGH | keep-module-latest 命令注入漏洞 |
| CVE-2023-26129 | 8.4 HIGH | bwm-ng 命令注入漏洞 |
| CVE-2023-26127 | 7.8 HIGH | n158 命令注入漏洞 |
| CVE-2023-2927 | 6.3 MEDIUM | JIZHICMS TemplateController.php index server-side request forgery |
| CVE-2023-2926 | 5.4 MEDIUM | SeaCMS Picture Upload member.php denial of service |
| CVE-2015-20108 | OneLogin ruby-saml 命令注入漏洞 |
No comments yet