References https://github.com/Chocapikk/CVE-2023-35885 https://www.sentinelone.com/vulnerability-database/cve-2023-35885/ https://pentest-tools.com/vulnerabilities-exploits/cloudpanel-remote-code-execution_17 https://qkl.seebug.org/vuldb/ssvid-99726 https://www.acunetix.com/vulnerabilities/web/cloudpanel-file-manager-auth-bypass-cve-2023-35885/ https://attackerkb.com/topics/41VW5OtDZs/cve-2023-35885 https://app.opencve.io/cve/?product=cloudpanel&vendor=mgt-commerce https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-35885.yaml https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/CloudPanel/CloudPanel%20RCE%E6%BC%8F%E6%B4%9E%20CVE-2023-35885.md https://github.com/Bu0uCat/CloudPanel-RCE
Related Vulnerabilities旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞PoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCccm-detect: Clear-Com Core Configuration Manager Panel - Detect智慧物联网综合服务平台ListFileManager存在目录枚举漏洞PoCctrlpanel-installer: CtrlPanel Installer ExposurePoCopcache-control-panel: Opcache control Panel - Unauthenticated AccessWP User Manager /profile/admin/about 文件包含漏洞(CVE-2026-9290)SteVe /steve/manager/signin 默认口令漏洞PoCCVE-2008-2052: Bitrix Site Manager 6.5 - Open RedirectPoCCVE-2026-9290: WP User Manager – User Profile Builder & Membership - Local File InclusionPoCcpanel-mailman-xss: cPanel Mailman - Cross-Site Scripting