Record summary

CVE-2017-17731 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 19, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALDedeCMS 5.7 - SQL InjectionCVSS 9.8

DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Apply the latest security patch or upgrade to a newer version of DedeCMS to mitigate the SQL Injection vulnerability.

WeaknessesCWE-89
Authorsj4vaovo
Template tagscvecve2017sqlidedecmsvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*
Shodan: http.html:"DedeCms"
Shodan: cpe:"cpe:2.3:a:dedecms:dedecms"
Shodan: http.html:"dedecms"
FOFA: app="DedeCMS"
FOFA: app="dedecms"
FOFA: body="dedecms"

Source: ProjectDiscovery

References

2