References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E6%8E%A5%E5%8F%A3ConfigResourceServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/yysfa/p/17414084.html https://www.ddpoc.com/DVB-2024-6776.html https://github.com/bmth666/Yongyou-Unserialize-plus https://blog.csdn.net/qq_39573664/article/details/135216549 https://stack.chaitin.com/vuldb/detail?id=591a76df-7c85-4ed7-8f63-5be7548b3bb3 https://cn-sec.com/archives/tag/%E7%94%A8%E5%8F%8Bnc https://mrxn.net/tag/%E7%94%A8%E5%8F%8B
Related Vulnerabilities思考軟體科技|EFence - 存在3個漏洞PoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2026-8236: Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata DisclosurePoCCVE-2026-8237: Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)PoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2026-53976: OpenChamber <1.13.0 - Unauthenticated Arbitrary File ReadPoCCVE-2026-6826: Concrete CMS <9.5.1 - Unauthenticated File Usage DisclosurePoCCVE-2026-24207: NVIDIA Triton Inference Server <= 26.02 - Authentication BypassVersa Concerto /portalapi/v1/roles/option 权限绕过漏洞(CVE-2025-34027)关于NC Cloud及YonBIP高级版系统的datacollectservlet接口漏洞安全通告PoCconcrete5-installer: Concrete5 - Installer Page Exposure关于NC系统BapAnaRepDefService的sql注入漏洞的安全通告OpenCATS /index.php 默认口令漏洞