漏洞描述 海康威视综合安防系统ISecureCenter是杭州海康威视数字技术股份有限公司旗下一款安防系统。海康威视iSecureCenter综合安防管理平台存在前台任意文件上传,攻击者可以未授权访问漏洞路由,直接上传恶意文件获取服务器权限。
相关漏洞推荐 金和OA AjaxForCenterBudgetDecompose.ashx SQL注入漏洞 POC CVE-2024-31223: Fides Privacy Center ≤ 2.39.1 - Server-Side URL Disclosure Atlassian Jira Software Data Center And Server 需授权 路径遍历漏洞 (CVE-2025-41250)VMware vCenter SMTP头部注入漏洞 华天软件InforCenter PLM uploadFileHttp 任意文件上传漏洞 POC 用友NC IMsgCenterWebService 命令执行漏洞 Cisco Secure Firewall Management Center和Cisco Secure Firewall Threat Defense 操作系统命令注入漏洞 POC CVE-2017-18542: Zendesk Help Center by BestWebSoft < 1.0.5 - Cross-Site Scripting POC CVE-2018-2791: Oracle Fusion Middleware WebCenter Sites - Cross-Site Scripting POC CVE-2018-3238: Oracle Fusion Middleware WebCenter Sites 11.1.1.8.0 - Cross-Site Scripting POC CVE-2018-7314: Joomla! Component PrayerCenter 3.0.2 - SQL Injection POC CVE-2019-11580: Atlassian Crowd and Crowd Data Center - Unauthenticated Remote Code Execution POC CVE-2019-12985: Citrix SD-WAN Center - Remote Command Injection