References https://rivers.chaitin.cn/blog/cqjfldh0lnedo7thq0u0 https://www.secrss.com/articles/63583 https://www.cnblogs.com/cookiescs/p/19510019 https://www.lmboke.com/archives/oracle-weblogic-server-jndizhu-ru-lou-dong-cve-2024-20931 https://www.ctfiot.com/161026.html https://blog.takake.com/posts/64101/ https://blog.csdn.net/A_991128a/article/details/137869548 https://www.cybersec-gd.cn/service/1808.html https://cn-sec.com/archives/2475902.html https://cdn.isc.360.com/isc-cxo/2024_Vulnerability_Report.pdf https://blog.csdn.net/Eaglecloud/article/details/136174131 https://www.broadcom.com/support/security-center/protection-bulletin/cve-2024-20931-oracle-weblogic-server-rce-vulnerability https://nvd.nist.gov/vuln/detail/cve-2024-20931 https://ccb.belgium.be/advisories/warning-proof-exploit-remote-code-execution-vulnerability-oracle-weblogic-server https://attackerkb.com/topics/GizBcG19y2/cve-2024-20931 https://github.com/gobysec/GobyVuls/blob/master/Weblogic_ForeignOpaqueReference_remote_code_execution_vulnerability_(CVE-2024-20931).md https://www.tenable.com/plugins/nessus/189176 https://medium.com/@vinayas23913/how-i-identified-and-exploited-an-oracle-weblogic-server-unauthenticated-remote-code-execution-f082fb95b428 https://www.fortiguard.com/encyclopedia/ips/54725 https://vuldb.com/vuln/251180 https://malware.news/t/latest-vulnerabilities-in-fortisiem-oracle-weblogic-apache-tomcat-cve-2024-23108-cve-2024-23109-cve-2024-20931-cve-2024-21733/78439 https://www.appsecure.security/vulnerability-database/cve-2024-20931/ https://firecompass.com/critical-cves-fortinet-oracle-postgresql-ws_ftp-server-and-more/ https://www.oracle.com/security-alerts/cpujan2024verbose.html https://www.securityweek.com/oracle-weblogic-vulnerability-exploited-in-the-wild/ https://stack.watch/product/oracle/ https://www.acunetix.com/vulnerabilities/web/oracle-weblogic-remote-code-execution-via-iiop/ https://notifications.qualys.com/product/2024/02/29/february-2024-web-application-vulnerabilities-released https://glassyamadeus.github.io/
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞PoCCVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request ForgeryPoCCVE-2026-45695: Kopia Server 0.23.0 - Remote Code ExecutionPoCCVE-2017-7504: JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java DeserializationPoCCVE-2026-23536: Feast Feature Server <=0.58.0 - Arbitrary File ReadPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL Injection網韻資訊|NewSiteServer (NSS) 新式校園網站系統 - Missing Authentication網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-35037: Ech0 < 4.2.8 - Server-Side Request ForgeryPoCCVE-2026-32255: Kan <= 0.5.4 - Server-Side Request ForgeryPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request Forgery