漏洞描述 远程代码执行漏洞是指攻击者通过某些漏洞在服务器上执行任意代码,这通常是由于应用程序对外部输入的验证不足或处理不当造成的。攻击者可以利用这个漏洞上传恶意代码或直接通过HTTP请求发送恶意代码,从而控制服务器,进行包括数据窃取、网站篡改、服务器资源滥用等在内的多种恶意行为。
相关漏洞推荐 POC CVE-2016-15043: WP Mobile Detector <= 3.5 - Unrestricted File Upload POC CVE-2024-35694: Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting POC grafana-metrics-exposure: Grafana Metrics Endpoint - Information Disclosure POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure ETAP Safety Manager 跨站脚本漏洞 东胜物流软件 /Areas/Mobile/Views/WMS/ZWCCX.aspx SQL 注入漏洞 POC CVE-2020-26836: SAP Solution Manager - Open Redirect POC bitrix-log-file-disclosure: Bitrix Site Manager - Log File Disclosure POC nexus-repository-anonymous-access: Nexus Repository Manager - Anonymous Access Enabled POC CVE-2019-25213: WordPress Advanced Access Manager - Path Traversal POC aem-anonymous-write: Adobe Experience Manager (AEM) - Anonymous JCR Node Creation 中成科信票务管理系统 /SystemManager/Api/TicketManager.ashx SQL 注入漏洞 新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞