References https://www.cnvd.org.cn/flaw/show/CNVD-2019-16798 https://www.secrss.com/articles/11382 https://www.ddpoc.com/DVB-2021-2092.html https://security.zone.ci/aliyun/ali_nonvd/260103.html https://avd.aliyun.com/detail?id=AVD-2021-904882 https://github.com/cqr-cryeye-forks/goby-pocs https://github.com/HimmelAward/Goby_POC/blob/main/README.md http://update1.hillstonenet.com/support/WAF_Help/en/1070210205.html https://www.hillstonenet.com/subscription-security-services/waf-update-service/1_1_146.html
Related VulnerabilitiesPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDORPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics DisclosurePoCCVE-2026-87820: CyberPanel 2.4.3-2.4.5 - AI Scanner Debug DisclosurePoCCVE-2017-8225: GoAhead Camera - Credential DisclosurePoCCVE-2026-55229: Gotenberg < 8.34.0 - Local File DisclosurePoCCVE-2025-53887: Directus < 11.9.0 - Version DisclosurePoCCVE-2026-42878: FacturaScripts - Unauthenticated phpinfo DisclosurePoCCVE-2026-0717: LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings DisclosurePoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information DisclosurePoCCVE-2026-8236: Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata DisclosurePoCCVE-2026-57219: RabbitMQ Management - OAuth 2 Client Secret DisclosurePoCCVE-2026-8237: Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)