References https://www.cnblogs.com/pursue-security/p/17666385.html https://github.com/zan8in/pocwiki/blob/main/%E4%B8%87%E6%88%B7%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%AC%E5%B9%B3%E5%8F%B0%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md https://zhuanlan.zhihu.com/p/653161860 https://blog.csdn.net/weixin_43981050/article/details/132476738 https://cn-sec.com/archives/1986838.html https://stack.chaitin.com/poc/detail/3461 https://blog.csdn.net/qq_33530840/article/details/140022967 https://www.cnblogs.com/priv/p/19296991
Related VulnerabilitiesPoCseaweedfs-unauth: SeaweedFS Filer - Unauthenticated AccessPoCmarimo-unauth: motionEye Partial - Authentication BypassPoClaravel-nova-unauth: Laravel Nova - Unauthenticated Admin Panel AccessPoClaravel-pulse-unauth: Laravel Pulse - Unauthenticated Dashboard AccessPoCpuppetdb-dashboard-unauth: PuppetDB Dashboard - Unauthenticated AccessPoCargo-workflows-unauth: Argo Workflows - Unauthenticated DashboardPoCnode-red-unauth: Node-RED - Unauthenticated AccessPoCchroma-db-unauth: Chroma DB - Information DisclosurePoC万户OA /defaultroot/evo/weixin/WeiXin!callback.action XML 外部实体注入漏洞PoCjboss-jmx-console-unauth: JBoss JMX Console - Unauthenticated Access万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞