CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable.
CVE
CVE-2020-18917
Severity
HIGH
CVSS
8.8
EPSS
0.84%
Original NVD Description
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Related CVEs
Other vulnerabilities affecting the same vendor(s)