在 PMWeb 7.x/8.x/2025.x 中发现了一个安全漏洞。该问题影响 file downloader.aspx 文件中某些未知的处理逻辑。通过对参数 FullFileName 或 FileName 的操控,可触发路径遍历(Path Traversal)漏洞。攻击者可远程发起利用该漏洞的攻击。该漏洞的利用代码已在公开渠道发布,可能被用于实际攻击。供应商在漏洞披露初期已被联系,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PMWeb | 7.* |
cpe:2.3:a:pmweb:pmweb:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100908 | 7.5 HIGH | Eyeplus p2pcam HTTP stack-based overflow |
| CVE-2026-101067 | 7.3 HIGH | dbgate save-uploaded-file Endpoint files.js saveUploadedFile path traversal |
| CVE-2026-101066 | 7.3 HIGH | dbgate Archive Link Creation archive.js createLink path traversal |
| CVE-2026-101005 | 7.3 HIGH | October CMS SSRF Protection ResizeImages.php validateExternalImageHost server-side request |
| CVE-2026-100909 | 7.3 HIGH | OctoberCMS ResizeImages.php getSourcePathForResize server-side request forgery |
| CVE-2026-101069 | 6.5 MEDIUM | dbgate Export databaseConnections.js exportModelSql path traversal |
| CVE-2026-101068 | 6.5 MEDIUM | dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal |
| CVE-2026-101083 | 5.3 MEDIUM | PMWeb encryptionhelper.dll information disclosure |
| CVE-2026-101070 | 5.3 MEDIUM | dbgate Files Endpoint runners.js files path traversal |
| CVE-2026-100907 | 5.3 MEDIUM | Eyeplus p2pcam Service snapshot information disclosure |
| CVE-2026-100906 | 5.3 MEDIUM | Eyeplus ONVIF Device GetUsers information disclosure |
No comments yet