FOFA[verified]@fofabotActive Exploitation
CVE-2025-0520, a high‑severity ShowDoc file‑upload vulnerability, is reported to be actively exploited, enabling PHP web‑shell remote code execution.
Cytex[verified]@cytexsmbActive Exploitation
The post warns that a long‑patched file‑upload flaw (CVE‑2025‑0520) in ShowDoc is actively exploited in the wild, with over 2,000 exposed instances, and urges immediate upgrade to v3.8.1.
Tathagata M.[verified]@tatha_gautamaActive Exploitation
The tweet reports that ShowDoc RCE flaw CVE‑2025‑0520 is actively exploited on unpatched servers, without providing a PoC or patch information.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
The tweet reports that ShowDoc's CVE-2025-0520 RCE flaw is actively exploited on unpatched servers, providing no PoC, exploit code, patch, or technical details.
Nicolas Krassas[verified]@DinosnActive Exploitation
The post reports that CVE-2025-0520, a Remote Code Execution flaw in ShowDoc, is being actively exploited on unpatched servers, but no PoC or exploit code details are provided in this excerpt.
TechNowPulse[verified]@TechNowPulseActive Exploitation
The post reports that CVE-2025-0520, a five-year-old ShowDoc flaw, is being actively exploited worldwide with web shells enabling remote code execution and full server takeover, and a patch is available.
TechNowPulse[verified]@TechNowPulseActive Exploitation
The article reports that ShowDoc CVE‑2025‑0520 is being actively exploited worldwide by deploying web shells that enable remote code execution and full server takeover, but it does not provide a PoC, patch, or exploit code details.
Vivek | Cybersecurity[verified]@VivekIntelActive Exploitation
ShowDoc’s previously patched CVE‑2025‑0520 file‑upload flaw is currently being actively exploited for server takeovers; urgent patching and web‑shell hunting are advised.