chiprook
← Security
SecurityOctober 7, 2026, 09:20

ShowDoc 3.9.2 flaw lets username field become PHP code

QiAnXin published QVD-2026-61708: ShowDoc 3.9.2 has an unauthenticated RCE in SQLite-backed deployments. The registerByVerify route lets attackers write PHP code into Sqlite/showdoc.db.php under the web root. It is fixed in version 3.9.3.

ShowDoc 3.9.2 flaw lets username field become PHP code
#ShowDoc#QiAnXin
Read next
Security

WordPress Click2Shell flaw lets hackers run PHP on the server

Security

Cloudflare to become a public certificate authority with post-quantum certificates

Policy

Utah becomes first state to let AI examine patients and prescribe medication

Software

SteamOS 3.9.2 Beta Adds Better Legion Go 2 Support, Fixes UI Bugs