漏洞描述 IBM Rational Publishing Engine(又名RPENG)是美国IBM公司的一套文档发布自动化解决方案。该方案支持文件和报告自动生成、自定义模板等。Document Builder是其中的一个创建文档的模块。 IBM Rational Publishing Engine 2.0.1版本中的Document Builder存在任意文件上传漏洞。远程攻击者可借助指定的文件扩展名利用该漏洞上传文件,执行任意代码。
相关漏洞推荐 WordPress AI Engine /wp-json/mcp/v1 信息泄露漏洞(CVE-2025-11749) (CVE-2023-53878)Member Login Script 3.3客户端去同步漏洞 POC CVE-2021-37415: Zoho ManageEngine ServiceDesk Plus - Authentication Bypass POC CVE-2023-23897: Ozette Plugins - Cross-Site Request Forgery POC wp-woocommerce-admin-fpd: WordPress Plugin WooCommerce Admin (woocommerce-admin) Full Path Disclosure POC CVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE) POC CVE-2021-4449: ZoomSounds Plugin - Unauthenticated Arbitrary File Upload POC CVE-2023-38875: PHP Login System 2.0.1 - Cross-Site Scripting POC CVE-2023-5815: News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion POC nginx-status-403-bypass: Nginx Status Page - 403 Bypass POC CVE-2022-29081: Zoho ManageEngine - Access Control Bypass POC CVE-2021-4449: ZoomSounds Plugin - Unauthenticated Arbitrary File Upload POC CVE-2021-4374: WordPress Automatic Plugin - Unauthenticated Options Change