Description 百卓Smart管理平台 uploadfile.php接口存在任意文件上传漏洞。未经身份验证的攻击者可以利用此漏洞上传恶意后门文件,执行任意指令,从而获得服务器权限并操纵服务器文件。
References https://mrxn.net/jswz/baizhuosmart-uploadfile-rce.html https://cn-sec.com/archives/2854887.html https://cn-sec.com/archives/2478282.html https://www.ddpoc.com/DVB-2023-5071.html https://mrxn.net/jswz/baizhuosmart-licence-rce.html https://github.com/Ice-001/POC-eeeeeeeeee-code https://www.ddpoc.com/DVB-2023-4643.html
Related Vulnerabilities旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞Apache Kafka UI /smartfilters/testexecutions 代码执行漏洞(CVE-2026-5562)易达科技ECMS /app/uploadFile 文件上传漏洞PoCCVE-2026-24423: SmarterMail - Remote Code ExecutionitC 中心管理服务器 /app/uploadFileApp.do 文件上传漏洞易宝 OA /SmartTradeScan/StockTake/SetScanQty txtBoxNo SQL 注入漏洞天地伟业 Easy7 /rest/file/uploadFile 文件上传漏洞太友 QSmart Audit 管理系统存在弱口令PoCSmarterMail ConnectToHub /api/v1/settings/sysadmin/connect-to-hub 命令执行漏洞(CVE-2026-24423)SmarterTools SmarterMail 远程代码执行漏洞(CVE-2026-24423)SmarterTools SmarterMail 权限管理不当漏洞PoCCVE-2026-23760: SmarterTools SmarterMail - Admin Password Reset