The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.Referenceshttp://tencent.comhttp://discuz.comhttps://github.com/FoolMitAh/CVE-2018-14729/blob/master/Discuz_backend_getshell.mdhttp://www.cnvd.org.cn/flaw/show/CNVD-2018-17059