References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E6%8E%A5%E5%8F%A3ConfigResourceServlet%E5%AD%98%E5%9C%A8%E5%8F%8D%E5%BA%8F%E5%88%97%E6%BC%8F%E6%B4%9E.md https://hackeyes.github.io/2021/04/16/%E7%94%A8%E5%8F%8BNC%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/ https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/%E7%94%A8%E5%8F%8Bnc/%E7%94%A8%E5%8F%8Bnc%206.5%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/ https://www.cnblogs.com/yysfa/p/17414084.html https://blog.nsfocus.net/nc/ https://github.com/bmth666/Yongyou-Unserialize-plus https://mrxn.net/jswz/yonyou-nc-ContactsQueryServiceServlet-rce.html https://cn-sec.com/archives/5125329.html https://jeyiuwai.pages.dev/posts/0-day-%E6%8C%96%E6%8E%98%E7%94%A8%E5%8F%8B-nc-modelhandleservlet-%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/ https://github.com/tzwlhack/Vulnerability/blob/main/%E7%94%A8%E5%8F%8BNC%206.5%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C.md
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-29962: HSC MailInspector - Local File InclusionPoCCVE-2026-85200: GEO my WP <=4.5.5.3 - Unauthenticated Local File Inclusion关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告关于NC Cloud及YonBIP高级版系统的公共入口接口漏洞安全通告畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞关于NC系统的任意文件下载漏洞的安全通告中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞思考軟體科技|EFence - 存在3個漏洞PoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path Traversal