References https://nvd.nist.gov/vuln/detail/CVE-2014-1841 https://www.exploit-db.com/exploits/31579 https://www.cve.org/CVERecord?id=CVE-2014-1841 https://cve.imfht.com/poc_detail/4ce0428ef55f48882afe3059447e8403cb56cb2c https://cve.imfht.com/detail/CVE-2014-1841 https://avd.aliyun.com/detail?id=AVD-2014-1843
Related Vulnerabilities畅捷通T+ERP系统SelectBackupFileOnServer接口处存在目录遍历漏洞PoCCVE-2026-10818: WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File UploadPoCserverless-framework-config-exposure: Serverless Framework - Configuration ExposurePoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated InitializePoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposurePoCCVE-2026-9103: Langflow OSS - Superuser Token IssuanceCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-56292: AcyMailing < 10.11.1 - Unauthenticated SQL InjectionPoCCVE-2026-58191: Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting