References https://avd.aliyun.com/detail?id=AVD-2021-890298 https://www.cnvd.org.cn/flaw/typeResult?typeId=29&max=20&offset=10420 https://avd.aliyun.com/detail?id=AVD-2021-890298 https://zone.ci/e/tags/?tagname=siteserver https://avd.aliyun.com/detail?id=AVD-2021-890298 https://www.cnvd.org.cn/flaw/show/CNVD-2022-66683 https://www.tenable.com/plugins/was/113879 https://www.tenable.com/plugins/was/113880 https://github.com/siteserver/cms/issues/3237 https://github.com/siteserver/cms/issues/3491 https://github.com/we1h0/SiteServer-CMS-Remote-download-Getshell https://qkl.seebug.org/vuldb/ssvid-89960 https://www.cnblogs.com/0x28/p/14380457.html https://github.com/jas502n/sangfor/blob/master/1earn/Security/RedTeam/Web%E5%AE%89%E5%85%A8/BS-Exploits.md https://gitee.com/J_tonight/FrameVul
Related Vulnerabilities網韻資訊|NewSiteServer (NSS) 新式校園網站系統 - Missing Authentication網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadSiteServer CMS CVE-2021-42654远程代码执行漏洞SiteServer CMS CVE-2021-42656 跨站脚本漏洞SiteServer CMS CVE-2021-42655 SQL注入漏洞SiteServerCMS 安全漏洞(CVE-2022-36226)SiteServer CMS forget.aspx-SQL注入SiteServer CMS 3.6.4 modal_contentTagAdd.aspx TagName参数-SQL注入siteserver CMS count.aspx页面userName参数-SQL注入siteserver CMS 3.6.4 background_fileTree.aspx-信息泄露siteserver_3.6.4-目录遍历siteserver CMS 3.6.4 console_logSite.aspx页面UserName参数-SQL注入siteserver CMS 3.6.4 background_nodeGroup.aspx页面PublishmentSystemID参数-SQL注入