References https://www.twcert.org.tw/newepaper/cp-151-8003-5543e-3.html https://www.twcert.org.tw/tw/cp-132-8003-5543e-1.html https://www.twcert.org.tw/tw/lp-132-1-13-20.html https://cve.imfht.com/detail/CVE-2024-7729 https://www.openinfosec.com/zh/shareArticle/content/382 https://www.twcert.org.tw/tw/lp-132-1-5-60.html
Related Vulnerabilities上海小羚羊软件股份有限公司小羚羊ERP系统downloadView存在任意文件读取漏洞鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File Upload仁和兴业(深圳)软件有限公司仁和云ERP attachmentdownloadAttachment 接口存在任意文件读取漏洞玉帛软件仓库管理系统DownloadFile存在任意文件读取漏洞安科瑞EMS企业微电网能效管理平台 /SubstationWEBV2/main/appDownload 文件读取漏洞云连ERP管理系统 /gateway/download!download.action 代码执行漏洞泛微 e-cology10 /papi/em/transform/downLoadSyslog 文件读取漏洞PoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information Disclosure方向标邮件网关 /common/cgi/download.cgi 代码执行漏洞通天星CMSV6车载视频监控平台 /808gps/StandardLoginAction_downLoad.action 文件读取漏洞天地伟业 Easy7 /Easy7/rest/downLoad/downLoadImage 文件读取漏洞PoCCVE-2021-4463: Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File DownloadPoClaravel-clockwork-exposure: Laravel Clockwork - Sensitive Information Exposure