A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
- https://www.exploit-db.com/exploits/37423/
- https://github.com/ARPSyndicate/cvemon