某些 WoltLab 产品存在通过缓存投毒导致的远程代码执行(RCE)漏洞,受影响版本为 WCF >= 6.1.0 至 < 6.1.23,以及 WCF >= 6.2.0 至 < 6.2.6。经过认证的、权限较低的用户可向由 WoltLab Suite Core 生成的可执行缓存文件中注入 PHP 代码。攻击者控制的数据可提前终止 nowdoc 解析块,从而注入任意 PHP 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71641 | EGO-Planner-v2交互缺陷致服务拒绝 | |
| CVE-2026-71644 | RACER FSM缺失默认分支致无人机碰撞 | |
| CVE-2026-78807 | wpa_supplicant <2.12 PMKSA缓存验证缺失 | |
| CVE-2026-71646 | RACER abcdef1234版FastExplorationFSM拒绝服务漏洞 | |
| CVE-2025-69904 | Linkstack v4.8.4及更早版本路径遍历漏洞 | |
| CVE-2026-79393 | 雄迈IPC Sofia服务堆溢出漏洞 | |
| CVE-2026-79395 | 雄迈相机IPC鉴权缺陷 | |
| CVE-2026-79394 | 雄迈摄像头XM530 RTSP服务默认禁用认证致数据泄露 | |
| CVE-2026-79396 | 雄迈IP摄像机XM530默认凭据硬编码 |
No comments yet