References https://www.cnblogs.com/pursue-security/p/17666147.html https://zhuanlan.zhihu.com/p/637165319 https://github.com/emadshanab/goby-poc/blob/main/AceNet-AceReporter-Report-component-Arbitrary-file-download.json https://stack.chaitin.com/vuldb/detail/46f4649f-1b89-4460-8b3a-d2173e97348c https://www.ddpoc.com/DVB-2023-4519.html https://github.com/Sec-Fork/POC-20241008
Related Vulnerabilities深信服DC数据中心管理系统 /src/sangforindex XML 外部实体注入漏洞PoCCVE-2025-15503: Sangfor OSM - Arbitrary File Uploadsangfor-vpn-supersession-rce: Sangfor VPN SuperSession TO RCEPoCCVE-2021-22502: Micro Focus Operations Bridge Reporter - Remote Code ExecutionPoCapache-solr-remotestreaming-anyfileread: Apache Solr RemoteStreaming 任意文件读取PoCsangfor-dc-sangforindex-xxe: 深信服 DC数据中心管理系统 sangforindex XML实体注入PoCsangfor-edr-arbitrary-admin-login: sangfor-edr-arbitrary-admin-loginPoCsangfor-edr-cssp-rce: Sangfor EDR 3.2.17R1/3.2.21 - Remote Code ExecutionPoCsangfor-logcent-rce: 深信服行为感知系统/日志中心 c.php 远程命令执行PoCsangfor-login-rce: 深信服 应用交付管理系统 login 远程命令执行漏洞PoCsangfor-ngaf-fileread: 深信服 NGAF 任意文件读取漏洞PoCsangfor-ngaf-login-rce: 深信服下一代防火墙NGAF login远程命令执行漏洞PoCsangfor-sg-catjs-fileread: 深信服 SG上网优化管理系统 catjs.php 任意文件读取