RainyGao DocSys
cpe:2.3:a:docsys_project:docsys:*:*:*:*:*:*:*
- <= 2.02.36
A path traversal vulnerability has been identified in RainyGao DocSys versions through 2.02.36. The issue arises in the file '/Doc/deleteDoc.do', where manipulation of the 'path' argument can lead to unauthorized file deletion on the server. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.
Exploitation of this vulnerability allows for arbitrary file deletion on the server.
To reproduce this vulnerability, send a request to the '/Doc/deleteDoc.do' endpoint with a crafted 'path' argument that exploits the path traversal flaw. This can be done by including directory traversal sequences in the 'path' argument to navigate outside of the intended directory and delete arbitrary files on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.