An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://opendocman.com | product |
https://github.com/opendocman/opendocman | third party advisory product |
https://github.com/opendocman/opendocman/issues/326 | issue tracking third party advisory |
https://github.com/opendocman/opendocman/issues/330 | issue tracking exploit third party advisory |