Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass, which may be automatically processed within the product's environment or lead to arbitrary code execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenDocMain 代码问题漏洞
Vulnerability Description
OpenDocMain是免费 PHP 文档管理系统 DMS。 OpenDocMain 1.4.4 版本存在安全漏洞,该漏洞源于add.php缺少对于文件上传的限制。攻击者可以使用MIME-bypass利用该漏洞将危险类型的文件上传到门户中实现任意代码执行。
CVSS Information
N/A
Vulnerability Type
N/A