CVE-2018-6910
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 19%
exploitation probability
19%top 3% of all CVEs
observed exploitation
nono source reports it
DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
Affected products
n/a · n/a