漏洞描述 Byzro Networks Smart S150是一款专业级上网行为管理设备。Byzro Networks Smart S150存在任意文件上传漏洞,该漏洞是由于userattestation.php接口对用户的请求验证不当导致的。
相关漏洞推荐 (CVE-2025-4617)Palo Alto Networks Prisma Browser截图控制绕过漏洞 (CVE-2025-4618)Palo Alto Networks Prisma Browser敏感信息泄露漏洞 POC Smartbi /imageimport.jsp 存在任意文件上传 百卓Smart uploadfile存在任意文件上传漏洞 smartbi-smartbi-bi-readfile: Smartbi smartbi_bi 任意文件读取 yongyou-grp-u8-smartupload01-fileupload: 用友 GRP u8 SmartUpload01 文件上传漏洞 CVE-2023-20888: VMware Aria Operations for Networks - Remote Code Execution Smartbi /vision/share.jsp 权限绕过漏洞 Smartbi 远程代码执行漏洞 POC CVE-2010-1657: Joomla! Component SmartSite 1.0.0 - Local File Inclusion POC CVE-2018-10141: Palo Alto Networks PAN-OS GlobalProtect <8.1.4 - Cross-Site Scripting POC CVE-2018-14064: VelotiSmart Wifi - Directory Traversal POC CVE-2018-3810: Oturia WordPress Smart Google Code Inserter <3.5 - Authentication Bypass