References https://www.twcert.org.tw/tw/cp-132-10268-1583b-1.html https://cnc.nptu.edu.tw/p/406-1007-185507,r1042.php?Lang=zh-tw https://cc.ncku.edu.tw/p/404-1213-285215.php?Lang=zh-tw https://isms.ccu.edu.tw/p/404-1044-77139.php?Lang=zh-tw https://www.twcert.org.tw/newepaper/cp-151-10268-1583b-3.html https://www.nchu.edu.tw/news-detail.php?id=60045 https://www.nutn.edu.tw/information_details.html?boardno=99936&classid=3 https://tp2rc.tanet.edu.tw/taxonomy/term/33?page=33
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionWordPress WebStack主题 /wp-admin/admin-ajax.php 文件上传漏洞(CVE-2026-1555)CentreStack 本地文件包含漏洞(CVE-2025-11371)全程云 /OA/api/2.0/HR/EntryApply/GetBaseData SQL 注入漏洞Apache CloudStack /client/api/ 默认口令漏洞Gladinet CentreStack & Triofox /storage/filesvr.dn 文件读取漏洞(CVE-2025-14611)ERPNext /api/method/erpnext.stock.doctype.material_request.material_request.get_material_requests_based_on_supplier SQL 注入漏洞(CVE-2025-52039)PoCCVE-2025-62613: VDO.Ninja - DOM-Based Cross-Site ScriptingPoCservicestack-requestlogs: ServiceStack Request Logs - Unauthenticated AccessPoCCVE-2025-14611: Gladinet CentreStack & Triofox - Hardcoded Credentials(CVE-2025-14611)Gladinet CentreStack和Triofox AES加密硬编码漏洞导致任意文件包含及安全降级易达科技-ECMS getProjectBaseDocData SQL注入漏洞PoC易达科技-ECMS getProjectBaseDocData 存在SQL注入漏洞