References https://www.twcert.org.tw/tw/cp-132-6886-2c546-1.html https://www.twcert.org.tw/newepaper/cp-151-6886-2c546-3.html https://cve.imfht.com/detail/CVE-2022-39059 https://db.gcve.eu/vuln/cve-2022-39059 https://www.thehackerwire.com/vulnerability/CVE-2022-39059/ https://www.twcert.org.tw/en/cp-139-6890-86f8a-2.html https://ttrc.nttu.edu.tw/p/16-1078-132505.php?Lang=zh-tw https://net.nthu.edu.tw/netsys/mailing:announcement:20230202_02 https://www.twcert.org.tw/tw/lp-132-1-8-60.html
Related VulnerabilitiesPoCCVE-2022-27925: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path TraversalPoCCVE-2026-87902: WordPress Core - PHP Template Path TraversalPoCCVE-2026-58467: Cockpit CMS <= 2.14.0 - Path Traversal / Local File InclusionPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-44177: Kirby CMS 5.3.0-5.4.0 - Path TraversalPoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2026-54917: SeaweedFS <= 4.29 - Path Traversal File WritePoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCnodogsplash-lfi: Nodogsplash - Directory TraversalPoCCVE-2025-71324: Flowise - Path TraversalPoCCVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)PoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path Traversal