References https://starlabs.sg/advisories/24/24-6781/ https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/Calibre/Calibre%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E(CVE-2024-6781).md https://www.hnitns.com/index.php?id=282 https://k0u1g.cn/VulnLib/%E6%BC%8F%E6%B4%9E%E5%BA%932024.html#calibre%E4%BB%BB%E6%84%8F%E6%96%87%E8%AF%BB%E6%B4%9E%E5%A4%B4-cve-2024-6781 https://s4e.io/tools/calibre-arbitrary-file-read-cve-2024-6781 https://mdr.skyeye.qianxin.com/forum/share/4635 https://idocdown.com/app/articles/blogs/detail/17380 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6781.yaml
Related VulnerabilitiesJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞仁和兴业(深圳)软件有限公司仁和云ERPbackupexportall 接口存在任意文件读取漏洞PoCCVE-2025-13528: Feedback Modal for Website <= 1.0.1 - Unauthenticated Feedback ExportUniFi Access /api/ucore/backup/export 命令执行漏洞(CVE-2025-52665)FOGProject /fog/management/export.php 信息泄露漏洞(CVE-2025-58443)PoC迈普无线网络管理系统 /form/exportConfigByHttp 信息泄露漏洞Evertz SDVN /v.1.5/php/features/feature-transfer-export.php 命令执行漏洞(CVE-2025-4009)PoCCVE-2025-11693: Export WP Page to Static HTML <= 4.3.4 - Cookie ExposurePoCredis-exporter-metrics: Redis Exporter Metrics - ExposurePoCdownload-monitor-unauth-log-export: Download Monitor < 1.9.7 - Unauthenticated Download Log Export用友 NC /uapws/service/nc.itf.bd.crm.ICurrtypeExportToCrmService XML 外部实体注入漏洞用友 NC /uapws/service/nc.itf.bd.crm.ICustomerExportToCrmService XML 外部实体注入漏洞用友 NC /uapws/service/nc.itf.bd.crm.ICustomerExportToCrmService SQL 注入漏洞