Vulnerability Description: The version earlier than dedecms 5.7 has been greatly improved, and the version earlier than dedecms 5.6 has been fixed with severe 0-day uploads. The premise is that you have background permissions. The file manager plug-in provided by the system does not filter the file names uploaded and saved after editing. This causes the webshell vulnerability.
Keywords: Powered by DedeCMSV57_GBK
Vulnerability Testing:
1. Go to the background. The default value is dede,Http://www.bkjia.com/dedeIn the left-side Navigation Pane, choose module> auxiliary plug-in> File Manager (which is installed by default by the system. If not, install it in Plug-In Manager)> select new text (or file upload) ......
For example, enter the file name as needed, such as 1.php. Enter a sentence in the content. The same is true for the following uploads. If the file extension is not filtered, arbitrary files are uploaded.
Vulnerability repair:
Html "target = _ blank> DEDECMS ultimate security settings