References https://mrxn.net/jswz/baizhuosmart-licence-rce.html https://www.ddpoc.com/DVB-2023-5071.html https://blog.csdn.net/qq_60614981/article/details/133861337 https://mrxn.net/jswz/baizhuosmart-uploadfile-rce.html https://cn-sec.com/archives/2854887.html https://www.cnvd.org.cn/flaw/show/CNVD-2021-51416 https://www.cnvd.org.cn/flaw/show/CNVD-2020-28786 https://www.cnvd.org.cn/flaw/show/CNVD-2021-51332 https://www.cnvd.org.cn/flaw/show/CNVD-2021-34575
Related VulnerabilitiesPoCCVE-2026-58123: Hermes WebUI < 0.51.788 - Remote Code ExecutionPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionMLflow /api/2.0/mlflow/webhooks 服务器端请求伪造漏洞(CVE-2026-64849)PoCCVE-2026-64849: MLflow Webhook SSRF - Unauthenticated Full-Read via Redirect BypassPoCCVE-2025-26399: SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCEPoCweb-config: Web Configuration File - DetectPoCafterlogic-path-disclosure: AfterLogic Aurora and WebMail Pro < 7.7.9 - Full Path DisclosurePoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2025-13528: Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback ExportPoCCVE-2026-41432: New API < v0.12.10 - Stripe Webhook Bypass金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞金和OA /c6/JHSoft.Web.CostControl/BudgetExecution/VouchUpdate.aspx SQL 注入漏洞MicroweberCMS userfiles x存在路径穿越漏洞(CVE-2026-65694)