DedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or inc/inc_archives_functions.php.
- https://kongxin.gitbook.io/dedecms-5-7-bug/
- https://github.com/0ps/pocassistdb
- https://github.com/20142995/Goby
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/Elsfa7-110/kenzer-templates
- https://github.com/FDlucifer/firece-fish
- https://github.com/HimmelAward/Goby_POC
- https://github.com/NyxAzrael/Goby_POC
- https://github.com/Z0fhack/Goby_POC
- https://github.com/jweny/pocassistdb
- https://github.com/shanyuhe/YesPoc
- https://github.com/zhibx/fscan-Intranet