漏洞描述 远程代码执行漏洞是指攻击者通过某些漏洞在服务器上执行任意代码,这通常是由于应用程序对外部输入的验证不足或处理不当造成的。攻击者可以利用这个漏洞上传恶意代码或直接通过HTTP请求发送恶意代码,从而控制服务器,进行包括数据窃取、网站篡改、服务器资源滥用等在内的多种恶意行为。
相关漏洞推荐 CrafterCMS存在XSS漏洞(CVE-2023-4136) WordPress Verbalize 插件 /wp-admin/admin-ajax.php generate_code 文件上传漏洞(CVE-2024-49668) POC CVE-2020-9757: Craft CMS < 3.3.0 - Server-Side Template Injection POC CVE-2021-41749: CraftCMS SEOmatic - Server-Side Template Injection POC CVE-2023-4136: CrafterCMS Engine - Cross-Site Scripting POC CVE-2023-41892: CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution POC CVE-2024-37843: Craft CMS <=v3.7.31 - SQL Injection POC CVE-2024-56145: Craft CMS - Remote Code Execution via Template Path Manipulation POC CVE-2025-32432: CraftCMS - Remote Code Execution POC CVE-2023-41892: CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution POC guowei-hb1910-generate-rce: GuoWei HB1910 PBX generate.php Remote Command Execution POC zhiyuehr-generate-entityfromtable-sqli: 智跃人力资源管理系统存在SQL注入漏洞 POC cloudflare-transform-via-url-injection: Cloudflare Transform via URL - Image Injection