References https://blog.csdn.net/qq_36618918/article/details/135199281 https://www.xway.cn/bug/vulnerability.php?id=112&page=3 https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8-FileUpload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0.md https://www.ddpoc.com/DVB-2023-5441.html https://cloud.baidu.com/article/2773426 https://www.cnblogs.com/pursue-security/p/17685037.html https://blog.csdn.net/qq_36618918/article/details/135199744 https://cn-sec.com/archives/2262885.html
Related Vulnerabilitiesdahua-bitmap-fileupload: 大华智慧园区综合管理平台bitmap接口存在任意文件上传e-weaver-eoffice-webservice-upload-fileupload: E-Weaver EOffice webservice upload file uploadjeecgboot-commoncontroller-parserxml-fileupload: Jeecgboot commonController parserXml fileuploadyonyou-uploadicon-do-fileupload: 用友移动系统管理uploadIcon.do接口存在任意文件上传漏洞PoCbaiyi-mobilefront2-fileupload: 百易云资产管理运营系统mobilefront2前台文件上传漏洞PoCbangguanke-crm-ajax-upload-fileupload: 帮管客CRM客户管理系统-/index.php/upload/ajax_upload接口存在任意文件上传漏洞PoCchuangke-shangchuan-fileupload: 创客13星零售商城系统前台任意文件上传漏洞PoCdahua-zhyq-pio-fileupload: 大华智慧园区 前台 poi 文件上传PoCdahua-zhyq-video-fileupload: 大华 智慧园区综合管理平台 video 任意文件上传漏洞PoCdongsheng-uploadmailfile-fileupload: 东胜物流软件CommMngPrintUploadMailFile 任意文件上传漏洞PoCemobile-lang2sql-fileupload: 泛微移动管理平台E-mobile lang2sql接口存在任意文件上传PoCentsoft-crm-customeraction-entphone-fileupload: 浙大恩特CRM/entsoft/CustomerAction.entphone;.js?method=loadFile任意文件上传PoCentsoft-crm-mailaction-entphone-fileupload: 浙大恩特CRM/entsoft/MailAction.entphone;.js?method=loadFile任意文件上传