References https://www.twcert.org.tw/tw/cp-132-7968-ce2ef-1.html https://www.twcert.org.tw/en/cp-139-7974-0562f-2.html https://nvd.nist.gov/vuln/detail/CVE-2024-40723 https://access.redhat.com/security/cve/cve-2024-40723 https://47.101.61.67/detail?id=AVD-2024-40723 https://hackmd.io/@9dCJrgb6QHGd8dRfgHO0zg/rJqWf5XqR
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionWordPress WebStack主题 /wp-admin/admin-ajax.php 文件上传漏洞(CVE-2026-1555)CentreStack 本地文件包含漏洞(CVE-2025-11371)全程云 /OA/api/2.0/HR/EntryApply/GetBaseData SQL 注入漏洞Apache CloudStack /client/api/ 默认口令漏洞Windows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)ERPNext /api/method/erpnext.stock.doctype.material_request.material_request.get_material_requests_based_on_supplier SQL 注入漏洞(CVE-2025-52039)PoCCVE-2025-62613: VDO.Ninja - DOM-Based Cross-Site ScriptingPoCservicestack-requestlogs: ServiceStack Request Logs - Unauthenticated AccessPoCCVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded Credentials