CVE-2026-101082 PMWeb 路径遍历漏洞
影响远程攻击者可读取服务器任意文件
PMWeb 7.x/8.x/2025.x 的 downloader.aspx 页面存在路径遍历漏洞。攻击者通过操纵 FullFileName/FileName 参数可读取服务器上的任意文件,且利用代码已公开。
影响范围
PMWeb 7.x、8.x、2025.x 版本受影响,具体受影响版本范围暂无更精确公开信息。
漏洞详情
漏洞类型为路径遍历(目录穿越)。downloader.aspx 在处理 FullFileName/FileName 参数时未对路径进行充分校验,攻击者可构造包含 ../ 的路径跳出预期目录,从而访问服务器上的敏感文件。该漏洞可远程触发,且公开的利用代码已存在。
利用条件与风险
攻击者无需认证即可远程发起请求,利用门槛低;由于 PoC 已公开,实战中被扫描和利用的风险较高,可能导致配置文件、源码等敏感信息泄露。
修复建议
厂商在披露前已被联系但未作回应,暂无官方补丁信息。临时缓解措施包括:对 downloader.aspx 的访问进行限制或鉴权、在 WAF 中拦截路径遍历特征请求、对 FullFileName/FileName 参数做白名单校验。
A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown processing of the file downloader.aspx. This manipulation of the argument FullFileName/FileName causes path traversal. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.