漏洞描述 Topaz Systems SigPlus Pro ActiveX Control 3.95版本,也可能在4.29之前的其他版本中存在设计错误漏洞。远程攻击者可以通过调用暴露的不安全(1)SetLogFilePath和(2)SigMessage方法创建带有任意内容的任意文件,并借此执行任意代码。
相关漏洞推荐 POC CVE-2022-29081: Zoho ManageEngine - Access Control Bypass POC CVE-2025-12480: Triofox - Improper Access Control POC CVE-2025-52665: UniFi Access - Broken Access Control JeeWMS /cgDynamGraphController.do SQL 注入漏洞 JeeWMS /departController.do SQL 注入漏洞 QNAP Systems Photo Station 跨站脚本漏洞 CVE-2019-19781: Citrix Application Delivery Controller (ADC) and Gateway Directory Traversal. jeecgboot-commoncontroller-parserxml-fileupload: Jeecgboot commonController parserXml fileupload 建文工程项目管理软件 /UserControl/FileUpload/FileUploadNew.ashx 文件上传漏洞 Dell KACE Systems Management Appliance (K1000)存在命令执行漏洞(CVE-2019-20504) Exrick Xboot Swagger SecurityController.java服务器端请求伪造(CVE-2025-8527) POC CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution POC CVE-2010-1340: Joomla! Component com_jresearch - 'Controller' Local File Inclusion