### [CVE-2018-6910](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6910) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php. ### POC #### Reference - https://kongxin.gitbook.io/dedecms-5-7-bug/ - https://kongxin.gitbook.io/dedecms-5-7-bug/ #### Github - https://github.com/0ps/pocassistdb - https://github.com/20142995/Goby - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/Elsfa7-110/kenzer-templates - https://github.com/FDlucifer/firece-fish - https://github.com/HimmelAward/Goby_POC - https://github.com/Z0fhack/Goby_POC - https://github.com/jweny/pocassistdb - https://github.com/shanyuhe/YesPoc - https://github.com/zhibx/fscan-Intranet