BugTracker.NET 的附件功能存在未受限制的文件上传漏洞。具有管理员权限的经过身份验证的用户可以修改应用程序配置,将文件存储到可通过 Web 接口访问的目录中。由于缺乏对文件扩展名的适当验证,攻击者可以上传恶意的 ASPX 文件,并在服务器上执行该文件。成功利用此漏洞将允许攻击者以 Web 服务所使用的账户权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BugTracker.NET | BugTracker.NET | all versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92531 | 7.5 HIGH | Improper Neutralization of Special Elements used in an OS Command in BugTracker.NET |
| CVE-2026-92533 | 7.1 HIGH | Path Traversal in BugTracker.NET |
No comments yet