S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-7700 Scanner

CVE-2018-7700 scanner - Remote Code Execution (RCE) vulnerability in DedeCMS

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-7700
8.8
CVSS

DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

DedeCMS is an open-source content management system that was developed for the purpose of managing, creating, and publishing digital content such as websites, blogs and web applications. The CMS is popularly used by web developers and website owners as it provides a comprehensive and user-friendly interface for managing content. DedeCMS makes use of a template engine that supports the development of custom themes and plugins which enables users to modify and extend its functionality.

CVE-2018-7700 is a vulnerability that was detected in DedeCMS 5.7 which can lead to arbitrary code execution when exploited. The vulnerability is caused by a Cross-Site Request Forgery (CSRF) attack which occurs when an attacker tricks an authenticated user into executing a task on a vulnerable application without their knowledge or consent. In this case, the partcode parameter in a tag_test_action.php request can be manipulated by an attacker to execute PHP code.

When the CVE-2018-7700 vulnerability is exploited, it can lead to remote code execution on the affected website. This means that an attacker can execute arbitrary PHP code on the targeted website which can cause damage, such as defacing the site, stealing sensitive information, and installing malicious software. The vulnerability can also expose the website's visitors to further security risks as their information may also be compromised.

At s4e.io, we understand the importance of identifying and addressing vulnerabilities in digital assets. With our pro features, readers can easily and quickly learn about potential vulnerabilities in their websites and web applications. We provide comprehensive security assessments and vulnerability scans to ensure that digital assets are secure and protected against cyberthreats. Protect your digital assets today by signing up for our pro features.

 

REFERENCES

Solution Advice

In order to protect against the CVE-2018-7700 vulnerability, there are several precautions that can be taken, including:

  • Keeping DedeCMS updated to the latest version to ensure that security patches are applied.
  • Using a web application firewall (WAF) to detect and prevent CSRF attacks.
  • Restricting access to sensitive administrative areas on the website and implementing multi-factor authentication for administrator accounts.
  • Adding input validation and sanitization to forms and other user-input elements in order to prevent malicious code from being executed.
  • Conducting regular security audits and penetration testing of the website to identify and patch vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-7700 scanner - Remote Code Execution (RCE) vulnerability in DedeCMS | S4E