ÐÛÂõÔÆÐ§ÀÍÆ÷ÄÚÖÃÓ²±àÂëÕË»§Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-10-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17919£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.1£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


º¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾XMeye P2PÔÆÐ§ÀÍÆ÷
ËùÓÐͨ¹ýº¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾´ú¹¤µÄ»ùÓÚXMeye P2PÔÆÐ§ÀÍÆ÷×°±¸


Îó²î¸ÅÊö


XMeye P2PÔÆÐ§ÀÍÆ÷ÊÇÒ»ÖÖÓÃÓÚNVR/DVR×°±¸ÖÎÀíµÄ×é¼þ£¬£¬£¬£¬Óɺ¼ÖÝÐÛÂõ¹«Ë¾Éú²ú¡£¡£¡£ ¡£¡£´Ë×é¼þ±»·¢Ã÷±£´æÄÚÖÃÓ²±àÂëµÄÕ˺Å£¬£¬£¬£¬¿É±»Ô¶³Ìͨ¹ýWeb½çÃæµÇ¼´Ó¶øÊµÏÖ·ÇÊÚȨµÄ×°±¸ÖÎÀí£¬£¬£¬£¬ËùÓÐʹÓôË×é¼þµÄ×°±¸¾ù´ËÇå¾²ÎÊÌâµÄÓ°Ïì¡£¡£¡£ ¡£¡£Í¬Ê±×°±¸»¹±£´æÏÔ×ŵÄĿ¼±éÀúÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ¶ÁȡϵͳÖеÄí§ÒâÎļþ£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎÊÌâ½øÒ»²½¿ØÖÆÏµÍ³»ñȡԶ³ÌÏÂÁîÖ´ÐеÄÄÜÁ¦¡£¡£¡£ ¡£¡£

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÖйúµØÇøÖÐÁÉÄþʡʹÓÃÓÃÊýÄ¿×î¶à£¬£¬£¬£¬¹²ÓÐ4582̨£»£»£»£»£» £»¹ã¶«Ê¡µÚ¶þ£¬£¬£¬£¬¹²ÓÐ1838̨£¬£¬£¬£¬É½¶«Ê¡µÚÈý£¬£¬£¬£¬¹²ÓÐ1566̨£¬£¬£¬£¬±±¾©ÊеÚËÄ£¬£¬£¬£¬¹²ÓÐ1492̨£¬£¬£¬£¬½­ËÕÊ¡µÚÎ壬£¬£¬£¬¹²ÓÐ1232̨¡£¡£¡£ ¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP


1¡¢Í¨¹ýWebÖÎÀí½çÃæµÇ¼ÄÚÖÃÓ²±àÂëÕ˺Å
ͨ¹ýä¯ÀÀÆ÷Ö±½Ó»á¼ûurl£¬£¬£¬£¬Ê¹ÓÃÓ²±àÂëÕË»§¼´¿ÉÖ±½ÓµÇ¼ÊÓÆµ¼à¿Ø½çÃæ¡£¡£¡£ ¡£¡£Ó²±àÂëÕË»§¼°¿ÚÁîΪ£ºdefault/¿Õ¿ÚÁî»òdefault/tluafed

ÈçÏÂÑÝʾ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÇ¼½øÈëºóµÄÖÎÀíÒ³Ãæ£º


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2¡¢ Web ServeĿ¼±éÀúÎó²î
XMeye P2PÔÆÐ§ÀÍÆ÷Web Server×é¼þȨÏÞÉèÖò»µ±£¬£¬£¬£¬µ¼Ö¿ÉÒÔ±éÀúĿ¼¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£ ¡£¡£ÒÔÏÂÒÔʵÑé»á¼û/../../../../../procΪÀý¡£¡£¡£ ¡£¡£


ÈçÏÂͼ£º

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÐÞ¸´½¨Òé


×Ô²éÒªÁ죺
Éó²éXMeye P2PÔÆÐ§ÀÍÆ÷×°±¸ÊÇ·ñ¿ªÆôWebÖÎÀí£¬£¬£¬£¬²¢Ê¹ÓÃÄÚÖÃÕË»§ÔÚWebÖÎÀí½çÃæÊµÑéµÇ¼¡£¡£¡£ ¡£¡£ÈôÉϰ¶Àֳɣ¬£¬£¬£¬ÔòÎó²î±£´æ¡£¡£¡£ ¡£¡£

Éý¼¶²¹¶¡£¡£¡£ ¡£¡£º
º¼ÖÝÐÛÂõÏÖÔÚ²¢Î´¾Í´ËÎó²îÐû²¼Èκβ¹¶¡£¬£¬£¬£¬Ïà¹ØÊÜÓ°ÏìÓû§ÇëÁªÏµº¼ÖÝÐÛÂõ¿Æ¼¼¼°Ïà¹Ø³§ÉÌ»ñȡ֧³Ö¡£¡£¡£ ¡£¡£

ÔÝʱ´¦Öóͷ£²½·¥£º
1¡¢Ê¹Óð×Ãûµ¥·½·¨ÏÞÖÆ¿É»á¼ûWEBÖÎÀíÆ½Ì¨µÄȪԴIP»ò¹Ø±ÕWEBÖÎÀíÆ½Ì¨¡£¡£¡£ ¡£¡£
2¡¢ÍâµØÍ¨¹ý´®¿ÚÐÞ¸ÄÄÚÖõÄrootÕË»§¿ÚÁî¡£¡£¡£ ¡£¡£

²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06
http://www.xiongmaitech.com/