CVSS v3
8.8
HIGH
EPSS Score
69.6%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by the filename=1.jpg.p*hp value.
An issue was discovered in DedeCMS V5.7 SP2. uploads/include/dialog/select_images_post.php allows remote attackers to upload and execute arbitrary PHP code via a double extension and a modified ".php" substring, in conjunction with the image/jpeg content type, as demonstrated by the filename=1.jpg.p*hp value.
Active exploitation of CVE-2018-20129 has not been confirmed. The EPSS score is 69.6%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2018-20129 has a CVSS v3 base score of 8.8 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).