漏洞描述 InTouch Access Anywhere 是InTouch 的扩展软件,使移动用户和临时用户能够通过兼容HTML5 的网络浏览器访问InTouch应用。其存在路径遍历,攻击者可读取敏感文件获取敏感信息。
相关漏洞推荐 POC CVE-2022-29081: Zoho ManageEngine - Access Control Bypass POC CVE-2025-12480: Triofox - Improper Access Control POC CVE-2025-52665: UniFi Access - Broken Access Control POC unifi-create-user: UniFi - Unauthenticated Creation Access For Users (CVE-2025-10035)Fortra GoAnywhere MFT License Servlet反序列化漏洞可能导致命令注入 bt742-pma-unauthorized-access: BT742 PMA Unauthorized Access tidb-unauth: TiDB - Unauthenticated Access POC CVE-2024-12356: Privileged Remote Access & Remote Support - Command Injection POC CVE-2005-3344: Horde Groupware Unauthenticated Admin Access POC CVE-2012-0896: Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access POC CVE-2016-1555: NETGEAR WNAP320 Access Point Firmware - Remote Command Injection POC CVE-2017-5868: OpenVPN Access Server 2.1.4 - CRLF Injection POC CVE-2017-7615: MantisBT <=2.30 - Arbitrary Password Reset/Admin Access