References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-nc.bs.sm.login2.RegisterServlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://cn-sec.com/archives/2604874.html https://github.com/adysec/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-cloud%20RegisterServlet%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://cloud.baidu.com/article/2774217 https://juejin.cn/post/7317844669228302371 https://cn-sec.com/archives/2617323.html https://github.com/Sec-Fork/POC-20250106/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-nc.bs.sm.login2.RegisterServlet%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.ddpoc.com/poc/DVB-2023-5443.html
Related VulnerabilitiesPoCCVE-2026-21589: Atlassian Jira/Confluence/Bitbucket - Pre-Auth Arbitrary File ReadPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoC用友NC /ebvp/infopub/showcontent SQL 注入漏洞关于U9 cloud存在命令执行漏洞的安全通告关于U9 cloud存在接口反序列化漏洞的安全通告PoCCVE-2026-58467: Cockpit CMS <= 2.14.0 - Path Traversal / Local File Inclusion关于NC系统的文件控制台SQL注入漏洞的安全通告PoCCVE-2026-9103: Langflow OSS - Superuser Token Issuance金蝶eascloud管理控制端任意文件上传PoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function Invocation