References https://blog.csdn.net/wasm7browser/article/details/153614817 https://www.cnblogs.com/qiushuo/p/17454530.html https://turinggu.github.io/2019/01/26/Information-leakage/ https://wiki.wgpsec.org/knowledge/web/infoleak.html https://www.tenablecloud.cn/plugins/nessus/14356 https://blog.csdn.net/2401_82760239/article/details/137460373 https://blog.pillar.fun/2020/03/02/%E5%A4%87%E4%BB%BD%E6%96%87%E4%BB%B6%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E/ https://cloud.tencent.com/developer/article/2389119 https://oopsdc.com/post/%E4%BF%A1%E6%81%AF%E6%B3%84%E9%9C%B2/ https://www.cnblogs.com/M4ny1u/p/13972246.html https://www.linuxidc.com/Linux/2014-11/109678.htm https://nvd.nist.gov/vuln/detail/CVE-2025-69200 https://portswigger.net/web-security/information-disclosure/exploiting https://www.exploit-db.com/exploits/24384 https://www.acunetix.com/blog/web-security-zone/how-to-stop-backup-leaking-sensitive-information/
Related Vulnerabilities仁和兴业(深圳)软件有限公司仁和云ERPbackupexportall 接口存在任意文件读取漏洞PoCCVE-2026-12898: All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File WritePoCCVE-2024-56064: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCEUniFi Access /api/ucore/backup/export 命令执行漏洞(CVE-2025-52665)指挥调度管理平台 /app/dbtool/db_backup_download.php 信息泄露漏洞PoCCVE-2023-6750: WordPress WP Clone <= 2.4.2 - Database Backup ExposurePoCCVE-2023-7165: JetBackup <= 2.0.9.7 - Sensitive Information Exposure via Directory ListingD-Link DNS-ShareCenter /cgi-bin/remote_backup.cgi 命令执行漏洞(CVE-2026-4196)PoCCVE-2026-1357: WPvivid Backup & Migration <= 0.9.123 - Arbitrary File UploadNginx UI /api/backup 未授权访问漏洞(CVE-2026-27944)PoCsweetrice-backup-disclosure: SweetRice CMS 1.5.1 - Backup DisclosurePoCovhcloud-backup-config: OVHcloud Backup Configuration - ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure