DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.
| Software | From | Fixed in |
|---|---|---|
| dedecms / dedecms | 5.7 | 5.7.x |
| dedecms / dedecms | 5.7-sp2 | 5.7-sp2.x |
| dedecms / dedecms | 5.7-sp1 | 5.7-sp1.x |
| dedecms / dedecms | - | 5.7 |