RSAS V6.0 Web Plugin Upgrade Package Upgrade List

Name: rsas-vulweb-V6.0R02F00.4101.dat Version:6.0.41.1
MD5:bcc43a061df27956fa2d5453858e2e03 Size:1.42M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4100 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4100 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4101 .

The upgrade package includes the following updates:
1. Add bShare vulnerability for redirecting to illegal websites Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-07-07 11:17:45
Name: rsas-vulweb-V6.0R02F00.4100.dat Version:6.0.41.0
MD5:6375dc2d6c5e042b1911b3b4f7c7b841 Size:1.88M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.40* . This upgrade package is a merged upgrade package. After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4100 .

This upgrade package involves the changes during upgrade from rsas-vulweb-V6.0R02F00.4001.dat to rsas-vulweb-V6.0R02F00.4008.dat .

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-07-06 18:52:49
Name: rsas-vulweb-V6.0R02F00.4008.dat Version:6.0.40.8
MD5:a561732498f233606adec6db44cc85b4 Size:1.41M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4007 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4007 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4008 .

The upgrade package includes the following updates:
1. Add WordPress 404to301 plugin SQL injection vulnerability (CVE-2015-9323) Plug-in.
2. Add WordPress Checklist plugin Cross-Site Scripting Vulnerability (CVE-2019-16525) Plug-in.
3. Add WordPress BuddyPress privilege escalation vulnerability (CVE-2021-21389) Plug-in.
4. Add WordPress Chop Slider SQL injection vulnerability (CVE-2020-11530) Plug-in.
5. Add Cross-site scripting vulnerability in WordPress download-manager plugin (CVE-2019-15889) Plug-in.
6. Add Cross-site scripting vulnerability in WordPress admin-font-editor plugin (CVE-2016-1000126) Plug-in.
7. Add WordPress plugin information disclosure vulnerability (CVE-2021-24226) Plug-in.
8. Add WordPress Canto plugin server-side request forgery vulnerability (CVE-2020-28976) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-07-03 15:07:55
Name: rsas-vulweb-V6.0R02F00.4007.dat Version:6.0.40.7
MD5:a0cbf3586fc4ddddd378fe73a10d8c0a Size:1.64M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4006 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4006 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4007 .

The upgrade package add 40 plugins, including but not limited to:
1. Add The WordPress FPSM Lite plugin is vulnerable to an open redirect vulnerability (CVE-2026-1296) Plug-in.
2. Add WordPress 3D FlipBook has an unauthorized data access vulnerability (CVE-2026-1314) Plug-in.
3. Add The WordPress WPvivid Backup plugin is vulnerable to an unauthorized arbitrary file upload issue (CVE-2026-1357) Plug-in.
4. Add The WordPress Video Conferencing with Zoom plugin is vulnerable to an authentication bypass vulnerability (CVE-2026-1368) Plug-in.
5. Add The WordPress WP Responsive Images plugin is vulnerable to a directory traversal issue (CVE-2026-1581) Plug-in.
6. Add The WordPress midi Synth plugin is vulnerable to an arbitrary file upload issue (CVE-2026-1306) Plug-in.
7. Add The WordPress Slider Future plugin is vulnerable to an arbitrary file upload issue (CVE-2026-1405) Plug-in.
8. Add Improper privilege management vulnerability in WordPress User Registration Membership plugin (CVE-2026-1492) Plug-in.
9. Add Ivanti Endpoint Manager authentication bypass vulnerability (CVE-2026-1603) Plug-in.
10. Add Cisco Secure Firewall Management Center security vulnerability (CVE-2026-20079) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-06-18 18:31:10
Name: rsas-vulweb-V6.0R02F00.4006.dat Version:6.0.40.6
MD5:b3f35e1ae0991109e11b26271d071d2a Size:1.64M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4005 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4005 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4006 .

The upgrade package includes the following updates:
1. Add CloudBees Jenkins Pipeline Groovy Plugin Security Feature Vulnerability (CVE-2019-1003030) Plug-in.
2. Add Confluence Data Center and Server remote code execution vulnerability in backend (CVE-2024-21683) Plug-in.
3. Add MLflow Job API - Authentication Bypass Vulnerability (CVE-2026-0545) Plug-in.
4. Add WordPress List Site Contributors plugin Reflective Cross-Site Scripting Vulnerability (CVE-2026-0594) Plug-in.
5. Add LolLMS server-side request forgery (CVE-2026-0560) Plug-in.
6. Add Langflow security vulnerability (CVE-2026-0770) Plug-in.
7. Add WordPress Frontend File Manager plugin missing authorization vulnerability (CVE-2026-0829) Plug-in.
8. Add WordPress URL Shortify plugin opens up a redirection vulnerability (CVE-2026-1277) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-06-05 17:43:34
Name: rsas-vulweb-V6.0R02F00.4005.dat Version:6.0.40.5
MD5:861b37c1fa3477f4026a5191f3133905 Size:1.67M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4004 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4004 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4005 .

The upgrade package includes the following updates:
1. Add XXL-JOB weak password Plug-in.
2. Add Dreamweaver dwsync.xml information disclosure vulnerability Plug-in.
3. Add FastAPI API documentation information leakage vulnerability Plug-in.
4. Add Unauthorized access to Golangexpvar page Plug-in.
5. Update Detection of JavaScript Framework/Library Vulnerability in Target Website Plug-in.
6. Update Pan Micro E-Cology remarkOperate Remote Code Execution Vulnerability Plug-in.
7. Update Weak Passwords Detected in Nacos Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-05-22 18:35:45
Name: rsas-vulweb-V6.0R02F00.4004.dat Version:6.0.40.4
MD5:a9502e7a10fa67f8824680cd43aead8a Size:1.35M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4003 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4003 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4004 .

The upgrade package includes the following updates:
1. Add Nginx remote code execution vulnerability (CVE-2026-42945) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-05-15 16:00:43
Name: rsas-vulweb-V6.0R02F00.4003.dat Version:6.0.40.3
MD5:286ba205889b5febdfe004fbc4643107 Size:1.59M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4002 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4002 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4003 .

The upgrade package add 35 plugins, including but not limited to:
1. Add Citrix NetScaler ADC and Citrix NetScaler Gateway Security Vulnerability (CVE-2025-12101) Plug-in.
2. Add SQL injection vulnerability (CVE-2019-12989) in Citrix Systems SDWAN Appliance and NetScaler SDWAN Appliance Plug-in.
3. Add Cleo Command Injection Vulnerability (CVE-2024-55956) Plug-in.
4. Add Dassault Systèmes DELMIA Apriso security vulnerability (CVE-2025-6204) Plug-in.
5. Add Dassault Systèmes DELMIA Apriso security vulnerability (CVE-2025-6205) Plug-in.
6. Add DNN encryption vulnerability (CVE-2018-15811) Plug-in.
7. Add DNN encryption vulnerability (CVE-2018-18325) Plug-in.
8. Add EyesOfNetwork has a vulnerability of insufficient credential protection (CVE-2020-8657) Plug-in.
9. Add Fortra GoAnywhere MFT remote code execution vulnerability (CVE-2025-10035) Plug-in.
10. Add FreePBX remote code execution vulnerability (CVE-2025-57819) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-05-09 17:48:57
Name: rsas-vulweb-V6.0R02F00.4002.dat Version:6.0.40.2
MD5:36aa998eb59dd95428c6a57232bbbe3b Size:1.34M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4001 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4001 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4002 .

The upgrade package includes the following updates:
1. Add Remote code execution vulnerability in TongWeb application server ejbserver of Tongdong Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-04-27 11:16:58
Name: rsas-vulweb-V6.0R02F00.4001.dat Version:6.0.40.1
MD5:d29816c2b41ffa27c0bd8b964dac0f5b Size:1.53M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.4000 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.4000 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4001 .

The upgrade package includes the following updates:
1. Add Default password vulnerability in Dubbo management backend Plug-in.
2. Add There is a weak password vulnerability in the Apollo management backend Plug-in.
3. Add There is a weak password vulnerability in the Grafana management backend Plug-in.
4. Add There is a weak password vulnerability in the XXL-JOB management backend Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-04-17 18:00:31
Name: rsas-vulweb-V6.0R02F00.4000.dat Version:6.0.40.0
MD5:25eede48d1e5e37f8f0d97d91fc16cc8 Size:1.65M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.39* . This upgrade package is a merged upgrade package. After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.4000 .

This upgrade package involves the changes during upgrade from rsas-vulweb-V6.0R02F00.3901.dat to rsas-vulweb-V6.0R02F00.3904.dat .

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-04-10 16:24:50
Name: rsas-vulweb-V6.0R02F00.3904.dat Version:6.0.39.4
MD5:99332d1f0ee66b7f374b10437c05e4e3 Size:1.52M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3903 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3903 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3904 .

The upgrade package includes the following updates:
1. Add The Dahua ICC intelligent IoT management platform push service has a command execution vulnerability Plug-in.
2. Add Dahua Intelligent IoT Integrated Management Platform receives and executes commands Plug-in.
3. Add There is a SQL injection vulnerability in the Dahua ICC intelligent IoT management platform at /ars/list Plug-in.
4. Add GeoServer XML External Entity Injection Vulnerability (CVE-2025-58360) Plug-in.
5. Add Arbitrary file reading in Hikvision IVMS Plug-in.
6. Add Struts2 remote command execution (CVE-2012-0393) Plug-in.
7. Add Rails Action Pack development redirection (CVE-2021-22881) Plug-in.
8. Update SourceMap Source Code File Disclosure Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-04-03 14:38:30
Name: rsas-vulweb-V6.0R02F00.3903.dat Version:6.0.39.3
MD5:c0ea62448be95d2b429853db9bee9980 Size:1.58M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3902 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3902 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3903 .

The upgrade package includes the following updates:
1. Update Next.js Middleware Privilege Bypass Vulnerability (CVE-2025-29927) Plug-in.
2. Update 1Pan Server Management Panel SQL Injection Vulnerability (CVE-24-39907) Plug-in.
3. Update Keking KkFileview Directory Traversal Vulnerability (CVE-2021-43734) Plug-in.
4. Update GeoServer XXE vulnerability (CVE-2025-30220) Plug-in.
5. Update Flask (Jinja2) Server-Side Template Injection (SSTI) Vulnerability Plug-in.
6. Update Grav CMS Server Template Injection SSTI Vulnerability (CVE-224-28116) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-03-20 17:40:03
Name: rsas-vulweb-V6.0R02F00.3902.dat Version:6.0.39.2
MD5:8b8bfe6adfbee8ecf8fda3ea264c9794 Size:1.55M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3901 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3901 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3902 .

The upgrade package includes the following updates:
1. Add Cisco HyperFlex HX Data Platform operating system command injection vulnerability (CVE-2021-1497) Plug-in.
2. Add Gladinet CentreStack and Gladinet TrioFox security vulnerability (CVE-2025-11371) Plug-in.
3. Add NextGen Mirth Connect security vulnerability (CVE-2023-43208) Plug-in.
4. Add Command injection vulnerability in Control Linear eMerge E3 Series operating system (CVE-2019-7256) Plug-in.
5. Add Sitecore and Sitecore XP code issue vulnerability (CVE-2019-9874) Plug-in.
6. Add Solarwinds Web Help Desk Java deserialization vulnerability (CVE-2024-28986) Plug-in.
7. Add SysAid On Prem security vulnerability (CVE-2025-2775) Plug-in.
8. Add SysAid On Prem security vulnerability (CVE-2025-2776) Plug-in.
9. Add Cross-site scripting vulnerability in WordPress Social Warfare plugin (CVE-2019-9978) Plug-in.
10. Add Vulnerability in ZOHO ManageEngine ServiceDesk Plus Authorization Issue (CVE-2021-37415) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-03-10 15:52:18
Name: rsas-vulweb-V6.0R02F00.3901.dat Version:6.0.39.1
MD5:6c62bdb4ddc47f0808285799b4986eba Size:1.38M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3900 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3900 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3901 .

The upgrade package includes the following updates:
1. Add Apache Struts XML External Entity Injection Vulnerability (CVE-2025-68493) Plug-in.
2. Add Tongda OA pda/appcenter/submenu.php SQL injection vulnerability (CVE-2024-10600) Plug-in.
3. Add The treeXml.jsp file of the Feiqi Interconnection FE enterprise operation management platform has a SQL injection vulnerability Plug-in.
4. Add The checkGroupCode.js interface of the Feiqi Interconnection FE enterprise operation management platform has a SQL injection vulnerability Plug-in.
5. Add "Jinhe OA C6 OpenFile.aspx back-end unauthorized sensitive file traversal vulnerability" Plug-in.
6. Add Jinhe OA HomeService.amxSQL injection Plug-in.
7. Add Multiple products of Suda Software Technology Co., Ltd., including doSavePrintTpl, are vulnerable to SQL injection Plug-in.
8. Update Detection of Weak Password on Target Web Application Form Plug-in.
9. Update The index.php file of the SeaCMS marine film and television management system is vulnerable to SQL injection (CVE-2024-44921) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-01-30 18:38:53
Name: rsas-vulweb-V6.0R02F00.3900.dat Version:6.0.39.0
MD5:726126848cfc0d226f7e8987a14cebae Size:4.45M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.38* . This upgrade package is a merged upgrade package. After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3900 .

This upgrade package involves the changes during upgrade from rsas-vulweb-V6.0R02F00.3801.dat to rsas-vulweb-V6.0R02F00.3811.dat .

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-01-09 18:23:00
Name: rsas-vulweb-V6.0R02F00.3811.dat Version:6.0.38.11
MD5:93815c618697bb96e048c70624d0763c Size:1.32M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3810 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3810 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3811 .

The upgrade package includes the following updates:
1. Add SQL injection vulnerability in WordPress Events Manager plugin (CVE-2025-6970) Plug-in.
2. Add Unauthorized information disclosure vulnerability in XWiki Platform (CVE-2025-29925) Plug-in.
3. Add WordPress HUSKY WooCommerce plugin directory traversal vulnerability (CVE-2025-1661) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2026-01-06 15:03:59
Name: rsas-vulweb-V6.0R02F00.3810.dat Version:6.0.38.10
MD5:cd34d268f7a972d4e7f4fbbdad06f64b Size:1.55M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3809 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3809 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3810 .

The upgrade package includes the following updates:
1. Add A compressed file vulnerability has been detected on the target site Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-12-19 17:50:46
Name: rsas-vulweb-V6.0R02F00.3809.dat Version:6.0.38.9
MD5:c5adfb053277412cd07f4c62d917fb79 Size:1.52M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3808 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3808 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3809 .

The upgrade package includes the following updates:
1. Update React/Next.js remote code execution vulnerability (CVE-225-55182/CVE-2025-66478) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-12-16 10:06:44
Name: rsas-vulweb-V6.0R02F00.3808.dat Version:6.0.38.8
MD5:761cfa5f495490ea1950cabec1ae4c24 Size:1.48M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3807 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3807 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3808 .

The upgrade package includes the following updates:
1. Add Adobe Experience Manager authentication bypass leads to remote code execution vulnerability (CVE-225-54253) Plug-in.
2. Add WeiPHP 5.0 arbitrary file read vulnerability (CVE-225-34045) Plug-in.
3. Add ETQ Reliance CG Platform SQLConverterServlet Reflective Cross Site scripting Vulnerability (CVE-225-34141) Plug-in.
4. Add Custom Login And Signup Widget WordPress plugin arbitrary code execution vulnerability (CVE-225-49029) Plug-in.
5. Add MCP Inspector Remote Code Execution Vulnerability (CVE-225-49596) Plug-in.
6. Add Cisco IOS XE Wireless LAN Controller arbitrary file upload vulnerability (CVE-225-20188) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-12-08 19:18:47
Name: rsas-vulweb-V6.0R02F00.3807.dat Version:6.0.38.7
MD5:61a85bc26dbbea11a93418d78fcbad60 Size:1.30M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3806 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3806 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3807 .

The upgrade package includes the following updates:
1. Add React/Next.js remote code execution vulnerability (CVE-225-55182/CVE-2025-66478) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-12-04 18:11:33
Name: rsas-vulweb-V6.0R02F00.3806.dat Version:6.0.38.6
MD5:0ed5f747dc8f6b10e6aa7a461f202251 Size:1.49M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3805 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3805 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3806 .

The upgrade package includes the following updates:
1. Add WordPress Uploader Plugin Multi Parameter Cross Site scripting (XSS) Vulnerability (CVE3-2287) Plug-in.
2. Add WordPress Advanced Dewplayer plugin directory traversal vulnerability (CVE3-7240) Plug-in.
3. Add WordPress Traffic Analyzer Plugin Cross Site scripting (XSS) vulnerability (CVE3-3526) Plug-in.
4. Add Xibo CMS directory traversal vulnerability (CVE3-5979) Plug-in.
5. Add WordPress dhtmlxSpreadsheet plugin cross site scripting vulnerability (CVE3-6281) Plug-in.
6. Update Target Site Detected to Use Swagger API Documents Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-11-24 18:31:32
Name: rsas-vulweb-V6.0R02F00.3805.dat Version:6.0.38.5
MD5:47ae5edb12fe7328a879fbfab4cfd0f4 Size:1.49M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3804 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3804 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3805 .

The upgrade package includes the following updates:
1. Add Webpack source code leak vulnerability Plug-in.
2. Add AVTECH AVN801 DVR Security Bypass Vulnerability (CVE3-4982) Plug-in.
3. Add WordPress plugin Duplicator Cross Site scripting vulnerability (CVE3-4625) Plug-in.
4. Add Cisco Unified Communications Manager directory traversal vulnerability (CVE3-5528) Plug-in.
5. Add Zimbra Collaboration Server skin parameter directory traversal vulnerability (CVE3-7091) Plug-in.
6. Add Telaen redir.php opens redirect vulnerability (CVE3-2621) Plug-in.
7. Add WordPress Category Grid View Gallery plugin ID parameter cross site scripting vulnerability (CVE3-4117) Plug-in.
8. Update Next.js Path Traversal Vulnerability (CVE-2017-16877) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-11-07 19:44:49
Name: rsas-vulweb-V6.0R02F00.3804.dat Version:6.0.38.4
MD5:05ad5e221ef439641b6ea860747f2b5f Size:1.30M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3803 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3803 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3804 .

The upgrade package includes the following updates:
1. Add Apache Tomcat path traversal vulnerability (CVE-225-55752) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-10-31 14:29:17
Name: rsas-vulweb-V6.0R02F00.3803.dat Version:6.0.38.3
MD5:49d7b8443223d808a6439b1111a01ee0 Size:1.30M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3802 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3802 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3803 .

The upgrade package includes the following updates:
1. Add WordPress Site Editor plugin version 1.1.1 and below contains a vulnerability in local files(CVE-2018-7422) Plug-in.
2. Add YongYou NC NCFindWeb Arbitrary File Read Plug-in.
3. Add seeyon OA A8 System htmlofficeServlet Remote Getshell Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-10-24 17:15:23
Name: rsas-vulweb-V6.0R02F00.3802.dat Version:6.0.38.2
MD5:b628d470cea188224c4a50146b63edff Size:4.35M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3801 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3801 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3802 .

The upgrade package includes the following updates:
1. Add There is a SQL injection vulnerability in the checkGroupCode.js interface of Feiqi Internet FE Enterprise Operation Management Platform Plug-in.
2. Update Target Site Detected to Use Swagger API Documents Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-10-10 18:42:27
Name: rsas-vulweb-V6.0R02F00.3801.dat Version:6.0.38.1
MD5:2df7a43dbec56f1f98036568083d7224 Size:1.35M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3800 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3800 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3801 .

The upgrade package includes the following updates:
1. Add Fansoft/View/ReportServer Remote Code Execution Vulnerability (CNVD-2024-30560) Plug-in.
2. Add Upload any file with Tumult Hype Animation less than or equal to 1.9.15(CVE-2024-11082) Plug-in.
3. Update Nacos JRaft arbitrary file read-write vulnerability (CNVD-2023-45001) Plug-in.
4. Update CZ Loan Management is less than or equal to 1.1 SQL Injection(CVE-2024-5975) Plug-in.
5. Update Woody AdSense ads less than or equal to 2.5.0 remote code execution(CVE-2024-3105) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-09-13 10:39:55
Name: rsas-vulweb-V6.0R02F00.3800.dat Version:6.0.38.0
MD5:f29b9acecec9bfb7cfa91e56efbcbd53 Size:3.90M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.37* . This upgrade package is a merged upgrade package. After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3800 .

This upgrade package involves the changes during upgrade from rsas-vulweb-V6.0R02F00.3701.dat to rsas-vulweb-V6.0R02F00.3739.dat .

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-09-06 20:32:50
Name: rsas-vulweb-V6.0R02F00.3739.dat Version:6.0.37.39
MD5:ae39b945379306bcdee195a2fdd9163f Size:1.71M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3738 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3738 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3739 .

The upgrade package add 223 plugins, including but not limited to:
1. Add MFolio Lite through 1.2.1 Authentication Bypass Vulnerability (CVE-224-9307) Plug-in.
2. Add WordPress Import Export For WooCommerce through1.5 arbitrary file upload vulnerability (CVE-224-54262) Plug-in.
3. Add WordPress Cwicked through1.4.0.2 Remote Code Execution (RCE) Vulnerability (CVE-2024-24707) Plug-in.
4. Add Widget Options remote code execution vulnerability (CVE-224-8672) Plug-in.
5. Add WordPress SurveyJS Plugin through1.9.136- Arbitrary File Upload Vulnerability (CVE-2024-50427) Plug-in.
6. Add LotsOfLocales unauthenticated local file contains vulnerability (CVE-224-12571) Plug-in.
7. Add SQL injection vulnerability in CIGESv2 system (CVE-2024-8161) Plug-in.
8. Add KEAP Opt in Forms through 2.0.1 Local file contains vulnerability (CVE-224-13725) Plug-in.
9. Add SQL injection vulnerability in School ERP Pro+Response 1.0 (CVE-224-4824) Plug-in.
10. Add Delta Electronics DVW Remote Command Injection Vulnerability (CVE-224-3871) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-08-30 19:57:48
Name: rsas-vulweb-V6.0R02F00.3738.dat Version:6.0.37.38
MD5:16820ee8379c3608a64c86d0b6fcfd4b Size:1.13M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3737 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3737 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3738 .

The upgrade package add 217 plugins, including but not limited to:
1. Add Apache Solr Velocity Template Injection Vulnerability (CVE9-17558) Plug-in.
2. Add Atlassian Crowd and Crowd Data Center uploadplugin.action plugin upload leads to code execution vulnerability (CVE9-11580) Plug-in.
3. Add Cisco Adaptive Security Appliances Software Path Traverse Vulnerability (CVE-2020-3452) Plug-in.
4. Add Citrix ADC and Citrix Gateway has a remote code injection vulnerability (CVE-2020-8194) Plug-in.
5. Add Citrix ADC Remote Code Execution Vulnerability (CVE9-19) Plug-in.
6. Add Adobe ColdFusion Management Console Multiple Directory Traverse Vulnerability (CVE0-2861) Plug-in.
7. Add Apache Couchdb vertical permission bypass vulnerability (CVE7-12635) Plug-in.
8. Add DrayTek Vigor300B cgi bin/mainfunction.cgi command injection vulnerability (CVE-2020-8515) Plug-in.
9. Add WordPress up to 7.31 Database Abstraction API expandArguments SQL Injection (CVE4-3704) Plug-in.
10. Add Gitlabgraphql sensitive information leak vulnerability (CVE-2020-26413) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-08-21 17:20:35
Name: rsas-vulweb-V6.0R02F00.3737.dat Version:6.0.37.37
MD5:07ac774d1f268bce98ca05a9b82946d0 Size:1.24M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3736 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3736 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3737 .

The upgrade package includes the following updates:
1. Add RuoYi Druid component weak password vulnerability Plug-in.
2. Update SSL Certificate Name Hostname Mismatch Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-08-08 16:19:07
Name: rsas-vulweb-V6.0R02F00.3736.dat Version:6.0.37.36
MD5:b623d8f4bd62279531c9850c3f369e06 Size:1.08M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3735 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3735 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3736 .

The upgrade package includes the following updates:
1. Update SSL Certificate Name Hostname Mismatch Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-31 19:28:29
Name: rsas-vulweb-V6.0R02F00.3735.dat Version:6.0.37.35
MD5:e33b694fe8c18026e87f0de37a0607dd Size:1.10M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3734 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3734 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3735 .

The upgrade package includes the following updates:
1. Add Dahua Intelligent IoT Integrated Management Platform/menu/upload/img file upload vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-29 17:39:41
Name: rsas-vulweb-V6.0R02F00.3734.dat Version:6.0.37.34
MD5:02cac1d2adb93892a0817755b65d42c3 Size:1.08M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3733 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3733 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3734 .

The upgrade package includes the following updates:
1. Add Yonyou Space KSOA/note_desult/lokResult.jsp SQL injection vulnerability Plug-in.
2. Add Yonyou U8cloud/Servlet/ESBIkaterServlet deserialization vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-29 13:56:13
Name: rsas-vulweb-V6.0R02F00.3733.dat Version:6.0.37.33
MD5:3a5b39dafffc30cf083ef11efe1fbb69 Size:1.09M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3732 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3732 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3733 .

The upgrade package includes the following updates:
1. Add Yonyou U8 Cloud/Servlet/LoginVideoServlet interface deserialization Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-26 15:50:32
Name: rsas-vulweb-V6.0R02F00.3732.dat Version:6.0.37.32
MD5:7da2033a55cc6067a5678f0e882a78d6 Size:1.25M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3731 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3731 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3732 .

The upgrade package includes the following updates:
1. Add UFIDA U9/app/base/getFileStream arbitrary file read vulnerability Plug-in.
2. Add Zhibang International ERP/sysn/json/pcclient/CheckSealPwd.ashx SQL injection vulnerability Plug-in.
3. Add SQL injection vulnerability scanning plugin for Zhibang International ERP/SYSN/json/pcclient/GetPersonalSealData.ashx.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-26 12:49:14
Name: rsas-vulweb-V6.0R02F00.3731.dat Version:6.0.37.31
MD5:1682d056c6e7690920cae8d0db073c85 Size:1.29M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3730 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3730 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3731 .

The upgrade package includes the following updates:
1. Add SSL Certificate Name Hostname Mismatch Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-25 16:58:09
Name: rsas-vulweb-V6.0R02F00.3730.dat Version:6.0.37.30
MD5:ff834a02d646aa1e40fd128e121639bd Size:1.09M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3729 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3729 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3730 .

The upgrade package includes the following updates:
1. Add Yonyou NC/servlet/getFormItem/path has SQL injection vulnerability (CNVD-2025-06710) Plug-in.
2. Add Plug-in.
3. Add Microsoft Office SharePoint authorization spoofing vulnerability (CVE-225-49706) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-22 17:41:36
Name: rsas-vulweb-V6.0R02F00.3729.dat Version:6.0.37.29
MD5:76d20432f9f977891e6ccb527642e5da Size:1.05M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3728 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3728 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3729 .

The upgrade package includes the following updates:
1. Add Fanwei E-Cology FormmodeFieldBrowserServlet SQL injection vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-19 11:08:06
Name: rsas-vulweb-V6.0R02F00.3728.dat Version:6.0.37.28
MD5:daf67a21ac7b9971b3ba09428011ba5b Size:1.07M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3727 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3727 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3728 .

The upgrade package includes the following updates:
1. Update UFIDA u9 cloud/print/pdfdirectprint.aspx remote command execution vulnerability Plug-in.
2. Update UFIDA spacetime ksoa delu user.jsp SQL injection vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-18 15:22:14
Name: rsas-vulweb-V6.0R02F00.3727.dat Version:6.0.37.27
MD5:f6b5e185c44ccf55c0e9a68e3b35c717 Size:1.08M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3726 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3726 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3727 .

The upgrade package includes the following updates:
1. Add Arbitrary file reading vulnerability in Dahua DSS video surveillance platform Plug-in.
2. Update Cookie Missing SameSite Attribute or Having Improper Configuration Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-17 11:15:37
Name: rsas-vulweb-V6.0R02F00.3726.dat Version:6.0.37.26
MD5:541e4158552bd17e0a0a71d12dd217de Size:1.07M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3725 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3725 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3726 .

The upgrade package includes the following updates:
1. Add Zhongke Huilian aisearch arbitrary file upload vulnerability Plug-in.
2. Update UFIDA spacetime ksoa delu user.jsp SQL injection vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-16 11:32:50
Name: rsas-vulweb-V6.0R02F00.3725.dat Version:6.0.37.25
MD5:44fe9eb34469f6408d1a82cab49a77b7 Size:1.07M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3724 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3724 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3725 .

The upgrade package includes the following updates:
1. Add UFIDA spacetime ksoa delu user.jsp SQL injection vulnerability Plug-in.
2. Add UFIDA u9 cloud/print/pdfdirectprint.aspx remote command execution vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-15 17:35:41
Name: rsas-vulweb-V6.0R02F00.3724.dat Version:6.0.37.24
MD5:f75774e8a11b193ecddb1556721ddef1 Size:1.12M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3723 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3723 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3724 .

The upgrade package includes the following updates:
1. Add Fortiweb GUI SQL injection vulnerability (cve-2025-25257) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-14 17:04:56
Name: rsas-vulweb-V6.0R02F00.3723.dat Version:6.0.37.23
MD5:69a731269f8c3fa5e71937ea5df4949f Size:1.06M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3722 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3722 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3723 .

The upgrade package includes the following updates:
1. Add UFIDA spacetime ksoa/kmc/delu catalog.jsp SQL injection vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-12 17:58:56
Name: rsas-vulweb-V6.0R02F00.3722.dat Version:6.0.37.22
MD5:7ebc1ee11e0a9418061259a64b3bf56d Size:1.05M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3721 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3721 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3722 .

The upgrade package includes the following updates:
1. Add Pan Micro E-Cology front-end SOL injection vulnerability Plug-in.
2. Add Dahua DSS front-end SSRF vulnerability Plug-in.
3. Add Dahua DSS /admin/cascade_deleteLinkedDev deserialization vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-11 15:33:42
Name: rsas-vulweb-V6.0R02F00.3721.dat Version:6.0.37.21
MD5:5a5a571e1e56f1877ab027a8b9d48c01 Size:1.25M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3720 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3720 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3721 .

The upgrade package includes the following updates:
1. Update Detection of Client (JavaScript) Cookie Reference on the Target URL Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-11 15:23:16
Name: rsas-vulweb-V6.0R02F00.3720.dat Version:6.0.37.20
MD5:46670da91eccaaecf9f203db2030477c Size:1.24M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3719 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3719 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3720 .

The upgrade package includes the following updates:
1. Add Pan Micro E-Cology remarkOperate Remote Code Execution Vulnerability Plug-in.
2. Add Sobey Rongmedia mchEditor arbitrary file upload vulnerability Plug-in.
3. Update Cookie Missing SameSite Attribute or Having Improper Configuration Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-09 16:43:56
Name: rsas-vulweb-V6.0R02F00.3719.dat Version:6.0.37.19
MD5:a31b60c4b8fce0b5436aafa2efcc33c1 Size:1.08M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3718 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3718 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3719 .

The upgrade package includes the following updates:
1. Add Dahua intelligent Internet of things integrated management platform (ICC) remote command execution and file upload Plug-in.
2. Add Yonyou space-time KSOA workslist SQL injection vulnerability Plug-in.
3. Update WordPress Verge3D Plugin Arbitrary File Upload Vulnerability (CVE-2023-51421) Plug-in.
4. Update Changjietong tplus AccountClearControler SQL injection vulnerability Plug-in.
5. Update Deserialization vulnerability in the EasySite system of Zhongke Huilian Plug-in.
6. Update FineReport Sail Soft Report IE/PDF Template Injection Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-07 19:28:58
Name: rsas-vulweb-V6.0R02F00.3718.dat Version:6.0.37.18
MD5:262ea50d414e10a64f5ac603674295d6 Size:1.06M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3717 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3717 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3718 .

The upgrade package includes the following updates:
1. Add Changjietong tplus AccountClearControler SQL injection vulnerability Plug-in.
2. Add FineReport Sail Soft Report IE/PDF Template Injection Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-05 20:57:45
Name: rsas-vulweb-V6.0R02F00.3717.dat Version:6.0.37.17
MD5:1cc979d4ca01de19fcb2c6d2290e10ba Size:1.22M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3716 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3716 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3717 .

The upgrade package includes the following updates:
1. Add Injection vulnerability in Fanwei e-cology9 Plug-in.
2. Add GeoServer XXE vulnerability (CVE-2025-30220) Plug-in.
3. Add Remote command execution vulnerability in the dbtest interface of the contract lock electronic signature system Plug-in.
4. Add Deserialization vulnerability in the EasySite system of Zhongke Huilian Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-07-02 15:33:12
Name: rsas-vulweb-V6.0R02F00.3716.dat Version:6.0.37.16
MD5:cb80709eb2860cacd082820d9fe153f7 Size:994.1K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3715 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3715 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3716 .

The upgrade package includes the following updates:
1. Update Cookie Missing SameSite Attribute or Having Improper Configuration Plug-in.
2. Update WebSphere Java Unserialize Remote Code Execution Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-06-30 09:45:17
Name: rsas-vulweb-V6.0R02F00.3715.dat Version:6.0.37.15
MD5:660e26abbf270511288dc0b948ade067 Size:1012.2K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3714 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3714 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3715 .

The upgrade package includes the following updates:
1. Update Cookie Missing SameSite Attribute or Having Improper Configuration Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-06-18 14:26:19
Name: rsas-vulweb-V6.0R02F00.3714.dat Version:6.0.37.14
MD5:d91fd65200f2fb7663315c26f534ccc2 Size:997.2K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3713 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3713 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3714 .

The upgrade package includes the following updates:
1. Add WordPress Verge3D Plugin Arbitrary File Upload Vulnerability (CVE-2023-51421) Plug-in.
2. Update Cookie Missing SameSite Attribute or Having Improper Configuration Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-06-13 17:12:13
Name: rsas-vulweb-V6.0R02F00.3713.dat Version:6.0.37.13
MD5:41d5c6cbeab22ae83f0ab8db0289c3aa Size:1.16M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3712 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3712 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3713 .

The upgrade package includes the following updates:
1. Add Ivanti Endpoint Manager Mobile Authentication Bypass and Remote Code Execution Vulnerabilities (CVE-2025-4427) and (CVE-2025-4428) Plug-in.
2. Add Cookie Missing SameSite Attribute or Having Improper Configuration Plug-in.
3. Add OSS Bucket Traversal Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-05-30 22:15:36
Name: rsas-vulweb-V6.0R02F00.3712.dat Version:6.0.37.12
MD5:57febb15384bde14ebea8cd3ea452ddc Size:1.22M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3711 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3711 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3712 .

The upgrade package includes the following updates:
1. Add Vulnerability Allowing CONNECT Method in HTTP Servers or HTTP Proxy Servers Plug-in.
2. Add Gladinet CentreStack Deserialization Code Execution Vulnerability (CVE-2025-30406) Plug-in.
3. Add Craft CMS generate-transform Deserialization Code Execution Vulnerability (CVE-2025-32432) Plug-in.
4. Add SAP Netweaver metadatauploader Remote Code Execution Vulnerability (CVE-2025-31324) Plug-in.
5. Add Commvault Command Center Directory Traversal Vulnerability (CVE-2025-34028) Plug-in.
6. Add mojoPortal Directory Traversal Vulnerability (CVE-2025-28367) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-05-16 20:47:31
Name: rsas-vulweb-V6.0R02F00.3711.dat Version:6.0.37.11
MD5:da5af432aedec2df97f7c3fb954773e3 Size:1.20M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3710 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3710 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3711 .

The upgrade package add 37 plugins, including but not limited to:
1. Add HJSOFT Human Resources Information Management System /common/org/loadtree SQL Injection Vulnerability Plug-in.
2. Add HJSOFT Human Resources Information Management System LoadOtherTreeServlet SQL Injection Vulnerability Plug-in.
3. Add Arbitrary File Read Vulnerability in /openFile.jsp Path of HJSOFT Human Resources Information Management System Plug-in.
4. Add HJSOFT Human Resources Information Management System report_org_collect_tree.jsp SQL Injection Vulnerability Plug-in.
5. Add HJSOFT Human Resources Information Management System DownLoadCourseware Arbitrary File Read Vulnerability Plug-in.
6. Add HJSOFT Human Resources Information Management System getSdutyTree SQL Injection Vulnerability Plug-in.
7. Add Jinhe OA AjaxServiceMethod Unauthorized Access Vulnerability Plug-in.
8. Add Jinhe OA C6 FileDownLoad.aspx Arbitrary File Read Vulnerability Plug-in.
9. Add Jinhe OA /C6/Control/UploadFileEditorSave.aspx Arbitrary File Upload Vulnerability Plug-in.
10. Add Jinhe OA /jc6/servlet/clobfield SQL Injection Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-04-25 11:05:44
Name: rsas-vulweb-V6.0R02F00.3710.dat Version:6.0.37.10
MD5:36d7be2ced9939b886700f77c87a3b2e Size:1007.5K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3709 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3709 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3710 .

The upgrade package includes the following updates:
1. Update Apache Log4j2 Remote Code Execution Vulnerability Plug-in.
2. Update HongFanOA ioassistance2.asmx SQL injection vulnerability Plug-in.
3. Update Hongfan ioffice OA ioFileExport.aspx arbitrary file read vulnerability Plug-in.
4. Update HongFan OA udfmr.asmx SQL injection vulnerability Plug-in.
5. Update Hongfan ioffice iorepsavexml.aspx file upload vulnerability Plug-in.
6. Update Wanhu OA DownloadServlet interface has arbitrary file reading vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-04-12 12:50:06
Name: rsas-vulweb-V6.0R02F00.3709.dat Version:6.0.37.9
MD5:187694453b5b68668370508d43be8aa7 Size:964.7K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3708 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3708 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3709 .

The upgrade package includes the following updates:
1. Add Vite Arbitrary File Read Vulnerability (CVE-2025-31125) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-04-09 11:04:32
Name: rsas-vulweb-V6.0R02F00.3708.dat Version:6.0.37.8
MD5:dae3a88a047bb4e099976c85a9f6ada6 Size:1.48M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3707 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3707 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3708 .

The upgrade package add 37 plugins, including but not limited to:
1. Add Next.js Middleware Privilege Bypass Vulnerability (CVE-2025-29927) Plug-in.
2. Add Hillstone Web Application Firewall (WAF) Unauthorized Command Injection Vulnerability Plug-in.
3. Add Weaver e-Bridge addTasteJsonp Interface SQL Injection Vulnerability Plug-in.
4. Add Hikvision clusters Interface Integrated Security Management Platform Arbitrary File Upload Vulnerability Plug-in.
5. Add Hikvision Camera authorize.action Weak Password Vulnerability Plug-in.
6. Add Hikvision Integrated Security System detection Interface RCE Vulnerability Plug-in.
7. Add Deserialization Vulnerability in /center/api/session of Hikvision Integrated Security Management Platform Plug-in.
8. Add Hikvision Integrated Security Management Platform keepAlive Fastjson Deserialization Vulnerability Plug-in.
9. Add Hikvision Integrated Security Management Platform config.properties Sensitive Information Disclosure Vulnerability Plug-in.
10. Add Hikvision Integrated Security Management Platform /resourceOperations/upload Arbitrary File Upload Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-03-30 08:37:52
Name: rsas-vulweb-V6.0R02F00.3707.dat Version:6.0.37.7
MD5:0e7c4c91aa8499f59cf76eb37e0d8c35 Size:1.11M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3706 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3706 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3707 .

The upgrade package includes the following updates:
1. Add Vite Arbitrary File Read Vulnerability (CVE-2025-30208) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-03-27 16:48:22
Name: rsas-vulweb-V6.0R02F00.3706.dat Version:6.0.37.6
MD5:2bf7668f08a61dd55d13f9ae910b9862 Size:994.7K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3705 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3705 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3706 .

The upgrade package includes the following updates:
1. Add Next.js Middleware Privilege Bypass Vulnerability (CVE-2025-29927) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-03-26 17:39:38
Name: rsas-vulweb-V6.0R02F00.3705.dat Version:6.0.37.5
MD5:999882ce04981d63eacbe383278d04d1 Size:1.26M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3704 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3704 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3705 .

The upgrade package add 110 plugins, including but not limited to:
1. Add E-SAFENET Electronic Document Security Management System getAllUsers Unauthorized Access Vulnerability Plug-in.
2. Add E-SAFENET Document Security Management System CDGAuthoriseTempletService1 Service SQL Injection Vulnerability Plug-in.
3. Add E-SAFENET Document Security Management System NetSecConfigAjax Interface “state” Parameter SQL Injection Vulnerability Plug-in.
4. Add E-SAFENET Document Security Management System LinkFilterService Remote Code Execution Vulnerability Plug-in.
5. Add E-SAFENET Document Security Management System CDGServer3 Log Information Disclosure Vulnerability Plug-in.
6. Add E-SAFENET Document Security Management System Arbitrary User Login Vulnerability Plug-in.
7. Add E-SAFENET Data Loss Prevention System NoticeAjax SQL Injection Vulnerability Plug-in.
8. Add E-SAFENET Document Security Management System DecryptionApp Interface Deserialization Vulnerability Plug-in.
9. Add E-SAFENET Document Security Management System Deserialization Vulnerability Plug-in.
10. Add E-SAFENET Document Security Management System LogDownLoadService SQL Injection Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-03-14 21:04:29
Name: rsas-vulweb-V6.0R02F00.3704.dat Version:6.0.37.4
MD5:c67795664345d3863f8afce4469f7e31 Size:1.19M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3703 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3703 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3704 .

The upgrade package add 87 plugins, including but not limited to:
1. Add E-SAFENET Electronic Document Security Management System /CDGServer3/CheckClientServelt Deserialization Vulnerability Plug-in.
2. Add E-SAFENET Electronic Document Security Management System /CDGServer3/document/UploadFileList;login Arbitrary File Download Vulnerability Plug-in.
3. Add E-SAFENET Electronic Document Security Management System /CDGServer3/EmailAuditService Deserialization Vulnerability Plug-in.
4. Add Deserialization Vulnerability in /CDGServer3/GetValidateLoginUserService of E-SAFENET Electronic Document Security Management System Plug-in.
5. Add Deserialization Vulnerability in /CDGServer3/SystemService of E-SAFENET Electronic Document Security Management System Plug-in.
6. Add Arbitrary File Upload Vulnerability in /DecryptApplicationService2 of E-SAFENET Electronic Document Security Management System Plug-in.
7. Add Arbitrary File Read Vulnerability in /solr/flow/debug/dump of E-SAFENET Electronic Document Security Management System Plug-in.
8. Add User Enumeration Vulnerability in /api/v4/users/ Interface of Gitlab Plug-in.
9. Add PHP Deserialization Vulnerability in Pikachu Plug-in.
10. Add Pikachu Server-Side Request Forgery (SSRF) Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-02-28 20:38:03
Name: rsas-vulweb-V6.0R02F00.3703.dat Version:6.0.37.3
MD5:100bf9074b6208960cfd355e6861099d Size:1.29M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3702 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3702 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3703 .

The upgrade package add 43 plugins, including but not limited to:
1. Add nginx /status Status Monitoring Interface Unauthorized Access Vulnerability Plug-in.
2. Add XXL-JOB Default Configuration Access Token Privilege Bypass Vulnerability Plug-in.
3. Add Tongda OA delete_seal.php SQL Injection Vulnerability (CVE-2023-4165) Plug-in.
4. Add Tongda OA delete_log.php SQL Injection Vulnerability (CVE-2023-4166) Plug-in.
5. Add Yonyou NC OAContactsFuzzySearchServlet Interface Deserialization Vulnerability Plug-in.
6. Add Yonyou NC saveXmlToFileServlet Interface Arbitrary File Upload Vulnerability Plug-in.
7. Add Yonyou NC /grouptemplet Interface Arbitrary File Upload Vulnerability Plug-in.
8. Add Yonyou NC saveImageServlet Interface Arbitrary File Upload Vulnerability Plug-in.
9. Add Yonyou NC /workflowImageServlet/doPost Interface SQL Injection Vulnerability Plug-in.
10. Add Sensitive Information Leakage in /uapws/service Path of Yonyou NC Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-02-17 18:35:43
Name: rsas-vulweb-V6.0R02F00.3702.dat Version:6.0.37.2
MD5:439c9e0c88cf281bbb2eab0cfb553394 Size:997.9K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3701 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3701 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3702 .

The upgrade package includes the following updates:
1. Add Palo Alto Networks PAN-OS Authentication Bypass Vulnerability (CVE-2025-0108) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-02-13 18:12:24
Name: rsas-vulweb-V6.0R02F00.3701.dat Version:6.0.37.1
MD5:b47cc775ec6fc7042b10a24f73d8b5a6 Size:2.17M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3700 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3700 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3701 .

The upgrade package includes the following updates:
1. Add target="_blank" Unsafe Vulnerability Plug-in.
2. Add Apache OFBiz Authentication Bypass Leading to Command Execution (CVE - 2023 - 51467) Plug-in.
3. Add Apache OFBiz Directory Traversal Leading to Code Execution Vulnerability (CVE-2024-32113) Plug-in.
4. Add Apache OFBiz SSRF and Remote Code Execution Vulnerability (CVE-2024-45507) Plug-in.
5. Add WP Umbrella plugin for WordPress Local File Inclusion Vulnerability (CVE-2024-12209) Plug-in.
6. Add Spring Framework Directory Traversal Vulnerability Under Specific Conditions (CVE-2024-38819) Plug-in.
7. Add Rejetto HTTP File Server Template Injection Vulnerability (CVE-2024-23692) Plug-in.
8. Add Dahua Intelligent Internet of Things Integrated Management Platform /evo-apigw/admin/API/Developer/GetClassValue.jsp Remote Command Execution Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2025-01-20 17:47:32
Name: rsas-vulweb-V6.0R02F00.3700.dat Version:6.0.37.0
MD5:d469f51dadd410deb322a867d2391272 Size:5.84M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.36* . This upgrade package is a merged upgrade package. After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3700 .

This upgrade package involves the changes during upgrade from rsas-vulweb-V6.0R02F00.3601.dat to rsas-vulweb-V6.0R02F00.3606.dat .

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2024-12-30 16:08:24
Name: rsas-vulweb-V6.0R02F00.3606.dat Version:6.0.36.6
MD5:ad1714eecd1ff4dd8f735feca2861ef9 Size:1.06M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3605 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3605 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3606 .

The upgrade package includes the following updates:
1. Add Shikong WMS ImageAdd.ashx File Upload Vulnerability Plug-in.
2. Add Shikong WMS File Upload Vulnerability Plug-in.
3. Add Yonyou GRP-U8 System getDeptName SQL Injection Vulnerability Plug-in.
4. Add Yonyou NC System Interface yerfile_down SQL Injection Vulnerability Plug-in.
5. Add Yonyou U8-CRM Interface rellistname.php SQL Injection Vulnerability Plug-in.
6. Add Yonyou GRP-U8 System taskmanager_login SQL Injection Vulnerability Plug-in.
7. Add Apache Solr Schema Designer RCE Vulnerability (CVE-2023-50292) Plug-in.
8. Add The Really Simple Security plugin for WordPress Authentication Bypass Vulnerability (CVE-2024-10924) Plug-in.
9. Add The YARPP plugin for WordPress Missing Authorization Vulnerability (CVE-2024-43919) Plug-in.
10. Add DATAGERRY - REST API Authentication Bypass Vulnerability (CVE-2024-46627) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2024-12-23 17:21:42
Name: rsas-vulweb-V6.0R02F00.3605.dat Version:6.0.36.5
MD5:f733edde438670b879fa693d950da9d4 Size:881.6K
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3604 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3604 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3605 .

The upgrade package includes the following updates:
1. Add Apache Struts2 S2-067 File Upload Vulnerability (CVE-2024-53677) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2024-12-17 13:58:09
Name: rsas-vulweb-V6.0R02F00.3604.dat Version:6.0.36.4
MD5:32366efa0e67686a887e1dc6185adab1 Size:1.07M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3603 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3603 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3604 .

The upgrade package includes the following updates:
1. Add Palo Alto Networks PAN-OS Authentication Bypass Vulnerability (CVE-2024-0012) Plug-in.
2. Add The WP Query Console plugin for WordPress Unauthorized Remote Command Execution Vulnerability (CVE-2024-50498) Plug-in.
3. Add Apache Solr Authentication Bypass Vulnerability (CVE-2024-45216) Plug-in.
4. Add Apache Solr Information Disclosure Vulnerability (CVE-2023-50290) Plug-in.
5. Add JeecgBoot Interface getTotalData Unauthorized SQL Injection Vulnerability (CVE-2024-48307) Plug-in.
6. Add Yonyou NC cartabletimeline SQL Injection Vulnerability Plug-in.
7. Add Yonyou NC Interface /portal/pt/task/process SQL Injection Vulnerability Plug-in.
8. Add Yonyou U8-CRM ajax/getufvouchdata.php SQL Injection Vulnerability Plug-in.
9. Add CenterSoft ERP System GetFile Arbitrary File Read Vulnerability Plug-in.
10. Add D-Link-NAS sc_mgr.cgi Command Execution Vulnerability Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2024-12-11 10:10:41
Name: rsas-vulweb-V6.0R02F00.3603.dat Version:6.0.36.3
MD5:ffd08d9f841c7501fff070ccaa881431 Size:5.68M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3602 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3602 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3603 .

The upgrade package includes the following updates:
1. Add Custom vulnerability detection plugin Plug-in.
2. Add CyberPanel upgrademysqlstatus Remote Command Execution Vulnerability (CVE-2024-51567 CVE-2024-51568) Plug-in.
3. Add VMware vSphere Client Path Traversal Vulnerability (CVE-2021-21972) Plug-in.
4. Add Zyxel NAS520 Operating System Command Injection Vulnerability (CVE-2020-9054) Plug-in.
5. Add Movable Type XMLRPC Operating System Command Injection Vulnerability (CVE-2021-20837) Plug-in.
6. Add MinIO Unauthorized Server-Side Request Forgery Vulnerability (CVE-2021-21287) Plug-in.
7. Add Apache Tomcat Deserialization Remote Code Execution Vulnerability (CVE-2020-9484) Plug-in.
8. Add Buffalo WSR-2533DHPL2 Path Traversal Vulnerability (CVE-2021-20090) Plug-in.
9. Add VICIdial Information Disclosure Vulnerability (CVE-2021-28854) Plug-in.
10. Add emlog Directory Traversal Vulnerability (CVE-2021-3293) Plug-in.
11. Add OpenOlat Directory Traversal Vulnerability (CVE-2021-27748) Plug-in.
12. Add systeminformation Command Injection Vulnerability (CVE-2021-21315) Plug-in.

Notes:
1. When the upgrade is completed, the engine automatically restarts, which will affect functions being used. Please perform the upgrade at an appropriate time.

Release Time:2024-11-22 17:37:09
Name: rsas-vulweb-V6.0R02F00.3602.dat Version:6.0.36.2
MD5:c341637a4c8cce7fa07332fc9e7cab26 Size:1.13M
Description:

This is a web plug-in upgrade package, which supports the web plug-in version of V6.0R02F00.3601 . This upgrade package is for incremental upgrade from the web plug-in version of V6.0R02F00.3601 . After upgrade, the system version remains unchanged, but the web plug-in version is updated to V6.0R02F00.3602 .

The upgrade package includes the following updates:
1. Add Vmware vSphere Client Improper Input Validation Vulnerability (CVE-2021-21985) Plug-in.
2. Add VMware vCenter Server Analytics Server Path Traversal Vulnerability (CVE-2021-22005) Plug-in.
3. Add WordPress Secure Copy Content Protection and Content Locking Plugin SQL Injection Vulnerability (CVE-2021-24931) Plug-in.
4. Add RaspAP Operating System Command Injection Vulnerability (CVE-2021-33357) Plug-in.
5. Add ZOHO ManageEngine Apache xmlsec Security Vulnerability (CVE-2022-47966) Plug-in.
6. Add Cobbler Remote Code Execution Vulnerability (CVE-2021-40323) Plug-in.
7. Add pf