References https://blog.pillar.fun/2020/03/02/%E5%A4%87%E4%BB%BD%E6%96%87%E4%BB%B6%E6%B3%84%E9%9C%B2%E6%BC%8F%E6%B4%9E/ https://www.cnblogs.com/qiushuo/p/17454530.html https://blog.csdn.net/carrot/article/details/153320176 https://www.cnblogs.com/M4ny1u/p/13972246.html https://cloud.tencent.com/developer/article/1969038 https://turinggu.github.io/2019/01/26/Information-leakage/ https://wiki.wgpsec.org/knowledge/web/infoleak.html https://portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-via-backup-files https://medium.com/@AhmadSopyan/information-disclosure-part-3-source-code-disclosure-via-backup-files-ce26138745c7 https://www.invicti.com/web-vulnerability-scanner/vulnerabilities/backup-file-disclosure https://docs.stackhawk.com/vulnerabilities/10095/ https://blog.csdn.net/yolo5detector/article/details/155287318
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传仁和兴业(深圳)软件有限公司仁和云ERPbackupexportall 接口存在任意文件读取漏洞PoCCVE-2026-0717: LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings DisclosurePoCCVE-2026-12898: All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File WritePoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCCVE-2024-56064: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCECisco ISE /admin/files-upload/ 文件上传漏洞(CVE-2025-20282)MicroweberCMS userfiles x存在路径穿越漏洞(CVE-2026-65694)UniFi Access /api/ucore/backup/export 命令执行漏洞(CVE-2025-52665)Langflow /api/v2/files 文件上传漏洞(CVE-2026-5027)CROWN REST files存在任意文件读取漏洞(CVE-2026-2330)指挥调度管理平台 /app/dbtool/db_backup_download.php 信息泄露漏洞易宝OA /api/files/DownloadFile2 文件读取漏洞