An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://halo.com | product |
https://github.com/halo-dev/halo | product |
https://notes.sjtu.edu.cn/s/s5oEvs-p5 | third party advisory exploit |
https://gist.github.com/b33t1e/a1a0d81b1173d0d00de8f4e7958dd867 |