漏洞描述 IBM Spectrum Control和IBM Storage Insights都是美国IBM公司的存储资源管理软件。 IBM Spectrum Control 5.2.8至5.2.10.1版本和IBM Storage Insights中存在任意文件上传漏洞。远程攻击者可通过发送特制的HTTP请求利用该漏洞上传恶意文件。
相关漏洞推荐 POC CVE-2021-20617: Acmailer - Improper Access Control to OS Command Injection POC CVE-2022-4940: WCFM Membership <= 2.10.0 - Broken Access Control POC CVE-2025-63387: Dify v1.9.1 - Broken Access Control POC gcs-bucket-listing: Google Cloud Storage - Public Bucket Listing Tinycontrol LAN Controller 安全漏洞 JeeWMS /rest/../cgUploadController.do 文件上传漏洞(CVE-2025-60268) POC CVE-2024-47308: Templately <= 3.1.2 - Broken Access Control POC CVE-2025-64525: Astro - Broken Access Control 友加畅捷管理系统 /Controllers/ajax/Attachment.ashx 文件读取漏洞 友加畅捷管理系统 /Controllers/ajax/downloadfile.ashx 文件读取漏洞 (CVE-2025-11461)Frappe CRM 1.53.1 Dashboard Controller SQL注入漏洞 POC CVE-2022-29081: Zoho ManageEngine - Access Control Bypass POC CVE-2025-12480: Triofox - Improper Access Control