RULE(RULE ID:337774)

Rule General Information
Release Date: 2024-01-09
Rule Name: I Doc View 2word Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: I Doc View Online Document Preview System is a set of systems for displaying and previewing various document types such as text documents, spreadsheets, presentations, PDF files, etc. in a web environment. There is a file upload vulnerability in the /html/2word online document preview system of I Doc View, which exists in the remote page caching function in I Doc View, because the application fails to perform sufficient security verification on the URL entered by the user, the attacker can make the server download the malicious file by constructing a special URL, so as to execute arbitrary code. The affected version is I Doc View < 13.10.1_20231115.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.