High severity8.8NVD Advisory· Published Aug 24, 2021· Updated Jun 17, 2026
CVE-2020-18917
CVE-2020-18917
Description
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Affected products
3Patches
Vulnerability mechanics
References
1- tusk1.cn/2019/05/12/DeDecms-v5-7-sp2-CRSF-%E6%96%87%E4%BB%B6%E6%93%8D%E4%BD%9C-%E5%89%8D%E5%8F%B0getshell/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.