漏洞描述 D-Security终端文件保护系统是一款专注于企业文件管理效率与安全的解决方案。该系统对文件进行全文加密,降低了被破解的风险,并被政府和国安局等情报单位认定为安全文件加密产品。系统的 /DLP/public/admintool/system_setting/sys_ds_logfile_displaylog.jsp 接口存在文件读取漏洞,攻击者可以通过构造恶意请求读取系统中的任意文件(如数据库配置文件、系统配置文件等),可能导致敏感信息泄露,进一步危害系统安全。
相关漏洞推荐 POC wp-all-in-one-wp-security-and-firewall-fpd: All In One WP Security & Firewall - Full Path Disclosure POC wp-better-wp-security-fpd: WordPress Plugin iThemes Security - Full Path Disclosure POC wp-better-wp-security-login-disclosure: WordPress Solid Security < 9.0.1 - Unauthenticated Login Page Disclosure Ksenia Security Lares 4.0 Home Automation 安全漏洞 ZKTeco ZKBio CVSecurity /app/v1/photoBase64 目录遍历漏洞(CVE-2024-35431) POC weak-csp-detect: Weak Content Security Policy - Detect POC wp-security-hidden-login-exposure: WordPress All-in-One Security <=4.4.1 - Hidden Login Page Exposure Cisco Secure Firewall Adaptive Security Appliance 缓冲区溢出漏洞 Vmware Spring Security 逻辑缺陷漏洞 Exrick Xboot Swagger SecurityController.java服务器端请求伪造(CVE-2025-8527) POC CVE-2019-14287: Sudo <= 1.8.27 - Security Bypass POC CVE-2014-6308: Osclass Security Advisory 3.4.1 - Local File Inclusion POC CVE-2016-4977: Spring Security OAuth2 Remote Command Execution