References https://github.com/Sec-Fork/POC-20241008/blob/main/%E5%BE%AE%E6%93%8E/%E5%BE%AE%E6%93%8E-AccountEdit-file-upload%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://www.ddpoc.com/DVB-2024-6280.html https://cn-sec.com/archives/2743556.html https://github.com/Sec-Fork/POC-20240918/blob/main/%E5%BE%AE%E6%93%8E/%E5%BE%AE%E6%93%8E-AccountEdit-file-upload%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://gitee.com/jacksongreen/POC/blob/main/%E5%BE%AE%E6%93%8E-AccountEdit-file-upload%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://mochazz.github.io/2019/11/11/%E5%BE%AE%E6%93%8E%E6%BC%8F%E6%B4%9E/
Related Vulnerabilities微擎 /payment/unionpay/notify.php SQL注入漏洞微擎 AccountEdit.aspx 任意文件上传漏洞微擎存在任意文件上传漏洞微擎存在鉴权绕过漏洞微擎管理系统存在弱口令漏洞微擎 /dock.ctrl.php 路径存在任意文件上传漏洞微擎系统 AccountEdit 文件 文件上传漏洞