0day5.com
http://0day5.com/archives/1346 CVE-2017-17731
CRITICALNuclei
dedecms dedecms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2017-17731 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 19, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dedecmsBrowse dedecms / dedecms | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALDedeCMS 5.7 - SQL InjectionCVSS 9.8
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest security patch or upgrade to a newer version of DedeCMS to mitigate the SQL Injection vulnerability.
WeaknessesCWE-89
Authorsj4vaovo
Template tagscvecve2017sqlidedecmsvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*
Shodan: http.html:"DedeCms"
Shodan: cpe:"cpe:2.3:a:dedecms:dedecms"
Shodan: http.html:"dedecms"
FOFA: app="DedeCMS"
FOFA: app="dedecms"
FOFA: body="dedecms"
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17731 https://nvd.nist.gov/vuln/detail/CVE-2017-17731 https://blog.csdn.net/nixawk/article/details/24982851 https://github.com/Lucifer1993/AngelSword/blob/232258e42201373fef1f323864366dc1499581fc/cms/dedecms/dedecms_recommend_sqli.py#L25 https://github.com/20142995/Goby
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-17731