An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585 | exploit |
https://github.com/star7th/showdoc/pull/1059 | patch issue tracking |
https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585 | third party advisory |