Description FileMage Gateway Windows Deployments 1.10.8及之前版本存在目录遍历漏洞,远程攻击者可利用该漏洞通过/mgmt/组件的特制请求获取敏感信息。
References https://nvd.nist.gov/vuln/detail/CVE-2023-39026 https://raindayzz.com/technicalblog/2023/08/20/FileMage-Vulnerability.html https://www.exploit-db.com/exploits/51708 https://github.com/advisories/GHSA-6m35-6x4j-hxjg https://cve.imfht.com/detail/CVE-2023-39026 https://www.sentinelone.com/vulnerability-database/cve-2023-39026/ https://www.filemage.io/docs/updates.html#change-log http://packetstormsecurity.com/files/174491/FileMage-Gateway-1.10.9-Local-File-Inclusion.html https://cve.imfht.com/analysis-public/CVE-2023-39026
Related Vulnerabilities云连ERP管理系统 /gateway/download!download.action 代码执行漏洞PoCCVE-2023-7327: Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File ReadPoCapache-casbin-mcp-gateway-default-login: Apache Casbin MCP Gateway - Default LoginPoCsanhuismg-radius-rce: Synway SMG Gateway 9-2radius.php - Remote Command ExecutionPoCremote-spark-gateway-config: Remote Spark Gateway Configuration/Credentials - ExposureOpenClaw Gateway 存在未授权访问漏洞Moltbot(Clawdbot)Gateways 未授权访问漏洞PoCambassador-api-diagnostics-exposure: Ambassador API Gateway Diagnostics - Exposure天地伟业Easy7综合管理平台 addGateWayOptLog SQL注入漏洞天地伟业easy7综合管理平台系统 addGateWayOptLog 存在SQL注入漏洞(CVE-2025-12101)NetScaler ADC和Gateway配置为网关或AAA虚拟服务器时的跨站脚本漏洞Spring Cloud Gateway SpEL 表达式注入漏洞