References https://www.cnblogs.com/pursue-security/p/17687951.html https://github.com/Phuong39/2022-HW-POC/blob/main/%E7%94%A8%E5%8F%8B%E6%97%B6%E7%A9%BAKSOA%E8%BD%AF%E4%BB%B6%E5%89%8D%E5%8F%B0%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/yang-miemie/p/17714927.html https://www.ddpoc.com/DVB-2022-3803.html https://cn-sec.com/archives/2193697.html https://buaq.net/go-158208.html https://blog.csdn.net/weixin_43981050/article/details/131324174 https://github.com/novysodope/fupo_for_yonyou https://cn-sec.com/archives/1852434.html
Related VulnerabilitiesPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL InjectionPoCCVE-2026-81578: PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-DirectPoCjohnson-controls-default-login: Johnson Controls Frick Quantum HD Compressors - Default LoginJoomShaper SP LMS /index.php?option=com_splms&view=cart 文件上传漏洞(CVE-2026-48909)綠色運算|NUMail - OS Command InjectionPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationPoCCVE-2020-10221: rConfig <= 3.9.4 - Authenticated OS Command Injection美麗島安全科技|4MOSAn GCB Doctor - OS Command InjectionPoCCVE-2026-19900: LB-LINK Routers - Unauthenticated Command InjectionPoCCVE-2026-71362: Adobe Commerce/Magento - Customer Session Identity SwitchPoCccm-detect: Clear-Com Core Configuration Manager Panel - DetectPoCsolarview-compact-pow-xss: SolarView Compact 6.00 - 'pow' Cross-Site ScriptingPoCsolarview-compact-time-begin-xss: SolarView Compact 6.00 - 'time_begin' Cross-Site Scripting