漏洞描述 【漏洞对象】云优cms开源城市分站管理系统 【涉及版本】1.1.5版本 【漏洞描述】该系统index文件orderby参数存在前台getshell,可能导致攻击者在服务器端任意执行代码,进而控制整个web服务器。
相关漏洞推荐 POC CVE-2016-15041: MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting POC CVE-2018-7765: Schneider Electric U.motion Builder - SQL Injection POC CVE-2019-12935: Shopware < 5.5.8 - Cross-Site Scripting POC CVE-2019-14206: Nevma Adaptive Images - Arbitrary File Deletion POC CVE-2020-19363: Vtiger CRM v7.2.0 - Directory Listing POC CVE-2021-28799: QNAP HBS 3 - Broken Access Control POC CVE-2021-37598: WP Cerber < 8.9.3 - Broken Access Control POC CVE-2023-33960: OpenProject < 12.5.4 - Project Identifiers Exposure POC CVE-2023-52163: Digiever DS-2105 Pro - Command Injection POC CVE-2024-29137: WordPress Tourfic Plugin <= 2.11.7 - Cross-Site Scripting POC CVE-2024-29792: Unlimited Elements for Elementor <= 1.5.93 - Cross Site Scripting POC CVE-2024-56159: Astro - Information Disclosure POC CVE-2025-4210: Casdoor - Authorization Bypass