WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://wikidocs.it/ | product |
https://demo.wikidocs.it/ | product |
https://github.com/Zavy86/WikiDocs | third party advisory |
https://github.com/Zavy86/WikiDocs/issues/28 | issue tracking exploit third party advisory |