A leaked absolute path vulnerability was discovered in doorGets v7.0.
There is a leaked absolute path vulnerability in ARTICLE if I upload file.
http://192.168.187.130/doorgets/dg-user/cn/?controller=moduleblog&uri=blog&lg=cn
First, add the article.
http://192.168.187.130/doorgets/dg-user/cn/?controller=moduleblog&uri=blog&action=add

Then, upload file.

File upload success and returned data packets

Modify the content-type value to text/html, you will find the absolute path in the packet.
