漏洞
dedecms任意文件上传漏洞
简介
dedecms变量覆盖漏洞导致任意文件上传。
文件
/include/dialog/select_soft_post.php
修复
打开 /include/dialog/select_soft_post.php 找到大概在72行
$fullfilename = $cfg_basedir.$activepath.'/'.$filename;
在它上面加入
if (preg_match('#\.(php|pl|cgi|asp|a...
漏洞
dedecms任意文件上传漏洞
简介
dedecms变量覆盖漏洞导致任意文件上传。
文件
/include/dialog/select_soft_post.php
修复
打开 /include/dialog/select_soft_post.php 找到大概在72行
$fullfilename = $cfg_basedir.$activepath.'/'.$filename;
在它上面加入
if (preg_match('#\.(php|pl|cgi|asp|a...