Skip to content

doorGets v7.0 will leak absolute path in FILE UPLOAD. #17

@SunJ3t

Description

@SunJ3t

A leaked absolute path vulnerability was discovered in doorGets v7.0.
There is a leaked absolute path vulnerability in ARTICLE if I upload file.
http://192.168.187.130/doorgets/dg-user/cn/?controller=moduleblog&uri=blog&lg=cn

First, add the article.
http://192.168.187.130/doorgets/dg-user/cn/?controller=moduleblog&uri=blog&action=add
image

Then, upload file.
image

File upload success and returned data packets
image

Modify the content-type value to text/html, you will find the absolute path in the packet.
image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions