References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/WSO2-fileupload-%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E-CVE-2022-29464.md https://rivers.chaitin.cn/blog/cq94ks90lnechd243keg https://zhuanlan.zhihu.com/p/569794219 https://avd.aliyun.com/detail?id=AVD-2022-29464 https://www.anquanke.com/post/id/273528 https://www.cnblogs.com/wavesky/p/16508069.html https://blog.csdn.net/weixin_41217671/article/details/131662466 https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2022/WSO2-2021-1738/ https://www.sentinelone.com/vulnerability-database/cve-2022-29464/ https://www.rapid7.com/db/modules/exploit/multi/http/wso2_file_upload_rce/ https://nvd.nist.gov/vuln/detail/CVE-2022-29464 https://cn-sec.com/archives/1108235.html https://www.cnblogs.com/lwh01/p/16193991.html https://www.4hou.com/posts/508A https://zone.huoxian.cn/d/2803-cve-2022-29464-wso2-api-manager
Related Vulnerabilities东胜物流软件 /Account/Chfee_payapplication/FileUpload 文件上传漏洞锐明技术Crocus系统 DeviceFileUpload.do 文件读取漏洞锐明技术 Crocus系统 DeviceFileUpload.do 任意文件读取漏洞锐捷EWEB路由器 /ddi/server/fileupload.php 文件上传漏洞锐明技术Crocus系统 DeviceFileUpload.do 任意文件读取漏洞MagicINFO SWUpdateFileUploader 文件上传漏洞dahua-bitmap-fileupload: 大华智慧园区综合管理平台bitmap接口存在任意文件上传e-weaver-eoffice-webservice-upload-fileupload: E-Weaver EOffice webservice upload file uploadjeecgboot-commoncontroller-parserxml-fileupload: Jeecgboot commonController parserXml fileupload