2020-12-08

Ðû²¼Ê±¼ä 2020-12-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_UnomiÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-13942][CNNVD-202011-1855]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýʹÓÃApache_UnomiµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐжñÒâ¹¥»÷£»£»£» Apache UnomiÊÇÒ»¸öJava¿ªÔ´¿Í»§Êý¾Ýƽ̨£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒ»¸öJavaЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÖÎÀí¿Í»§£¬£¬£¬£¬£¬£¬£¬Ç±ÔÚÖ÷¹ËºÍ»á¼ûÕßµÄÊý¾Ý²¢×ÊÖú¸öÐÔ»¯¿Í»§ÌåÑé¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Metinfo_common.inc.phpÔ¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMetinfoµÄcommon.inc.phpµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷¡£¡£¡£MetInfoÊÇÒ»¿îÊÊºÏÆóÒµ½¨Õ¾µÄ¿ªÔ´Ãâ·ÑCMS½¨Õ¾ÏµÍ³,10ÄêÂõÆ·ÅÆ,Ö§³Ö6ÖÖС³ÌÐò,ÏìӦʽ½á¹¹,¿ÉÊÓ»¯±à¼­,SEOÓѺÃ,Ö§³Ö¶àÓïÑÔ,ÍøÕ¾Ä£°å¸»ºñ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_Îļþ¶ÁÈ¡_metinfo_í§ÒâÎļþ¶ÁÈ¡Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMetinfoµÄÎļþ¶ÁÈ¡Îó²î¾ÙÐй¥»÷£»£»£»MetInfoÊÇÒ»¿îÊÊºÏÆóÒµ½¨Õ¾µÄ¿ªÔ´Ãâ·ÑCMS½¨Õ¾ÏµÍ³,10ÄêÂõÆ·ÅÆ,Ö§³Ö6ÖÖС³ÌÐò,ÏìӦʽ½á¹¹,¿ÉÊÓ»¯±à¼­,SEOÓѺÃ,Ö§³Ö¶àÓïÑÔ,ÍøÕ¾Ä£°å¸»ºñ

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ

HTTP_TRS_WCM_pre.asÎļþ°üÀ¨Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃTRS_WCMµÄÎļþ°üÀ¨Îó²î¾ÙÐй¥»÷£»£»£»TRSÄÚÈÝÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬£¬¼´TRS WCMÊÇÒ»¿îÃæÏòÕþ¸®¡¢Ã½ÌåºÍÆóÒµµÈÐÐÒµÓû§µÄÄÚÈÝÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬Ö§³ÖÔÚÔÆÅÌËã¼Ü¹¹ÉϾÙÐм¯Èº»¯°²ÅÅ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÖ§³ÖÄÚÈÝÖÎÀíÔÆÐ§ÀÍģʽ£¬£¬£¬£¬£¬£¬£¬Îª²î±ðµÄ¡¢¶à¼¶×éÖ¯»ú¹¹ÌṩÄÚÈݸ»ºñ¡¢ÐÎʽ¶àÑù¡¢¿ÉÀ©Õ¹µÄÄÚÈÝÖÎÀíÔÆÐ§ÀÍ£¬£¬£¬£¬£¬£¬£¬¾ßÓÐÓëÉ罻ýÌåÈںϡ¢Ò»´Î²É±à/¶àÇþµÀÐû²¼¡¢Ë鯬»¯Ðû²¼¡¢¿ÉÊÓ»¯×¨ÌâÖÆ×÷¡¢¸»Ã½ÌåÄÚÈÝÖÎÀíµÈ¹¦Ð§Ìصã¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_Îļþ°üÀ¨_Joomla_com_cckjseblodÎļþ°üÀ¨Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJoomlaµÄÎļþ°üÀ¨Îó²î¾ÙÐй¥»÷;Joomla!ÊÇÒ»Ì×È«Çò×ÅÃûµÄÄÚÈÝÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬£¬Õ¼ÓÐÈ«Çò6%µÄÍøÕ¾Êг¡·Ý¶î¡£¡£¡£ Joomla!ÊÇʹÓÃPHPÓïÑÔ¼ÓÉÏMySQLÊý¾Ý¿âËù¿ª·¢µÄÈí¼þϵͳ¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ÉÒÔÔÚLinux¡¢ Windows¡¢MacOSXµÈÖݪֲî±ðµÄƽ̨ÉÏÖ´ÐС£¡£¡£ÏÖÔÚÊÇÓÉOpen Source MattersÕâ¸ö¿ª·ÅÔ´Âë×éÖ¯¾ÙÐпª·¢ÓëÖ§³Ö£¬£¬£¬£¬£¬£¬£¬Õâ¸ö×éÖ¯µÄ³ÉÔ±À´×ÔÈ«Ììϸ÷µØ£¬£¬£¬£¬£¬£¬£¬Ð¡×é³ÉÔ±Ô¼ÓÐ150ÈË£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÁË¿ª·¢Õß¡¢Éè¼ÆÕß¡¢ÏµÍ³ÖÎÀíÕß¡¢Îļþ׫дÕߣ¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Áè¼Ý2ÍòÃûµÄ¼ÓÈë»áÔ±¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_ÆïÊ¿CMSÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÆïÊ¿CMSµÄassign_resume_tpl²ÎÊý¾ÙÐдúÂëÖ´ÐвÙ×÷£»£»£»ÆïÊ¿È˲ÅϵͳÊÇÒ»Ïî»ùÓÚPHP+MYSQLΪ½¹µã¿ª·¢µÄÒ»Ì×Ãâ·Ñ + ¿ªÔ´×¨ÒµÈ˲ÅÕÐÆ¸ÏµÍ³¡£¡£¡£ÎªÐ¡ÎÒ˽¼ÒÇóÖ°ºÍÆóÒµÕÐÆ¸ÌṩÐÅÏ¢»¯½â¾ö¼Æ»®, ÆïÊ¿È˲Åϵͳ¾ß±¸Ö´ÐÐЧÂʸߡ¢Ä£°åÇл»×ÔÓÉ¡¢ºǫ́ÖÎÀí¹¦Ð§ÎÞа¡¢Ä£¿£¿£¿£¿£¿£¿£¿é¹¦Ð§Ç¿Ê¢µÈÌØµã¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


1.png

2.png



ÊÂÎñÃû³Æ£º

HTTP_ÎļþÉÏ´«_Metinfo_savepathÎļþÉÏ´«Îó²î_¹¥»÷ʵÑé

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMetinfoµÄsavepath²ÎÊý¾ÙÐÐÎļþÉÏ´«Îó²î£»£»£»MetInfoÊÇÒ»¿îÊÊºÏÆóÒµ½¨Õ¾µÄ¿ªÔ´Ãâ·ÑCMS½¨Õ¾ÏµÍ³,10ÄêÂõÆ·ÅÆ,Ö§³Ö6ÖÖС³ÌÐò,ÏìӦʽ½á¹¹,¿ÉÊÓ»¯±à¼­,SEOÓѺÃ,Ö§³Ö¶àÓïÑÔ,ÍøÕ¾Ä£°å¸»ºñ

¸üÐÂʱ¼ä£º

20201208


3.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_APPcms_í§ÒâÎļþÏÂÔØÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

APPcms 1.3.708°æ±¾±£´æí§ÒâÎļþÏÂÔØÎó²î£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚpic.phpÖжԻá¼ûµÄurlÎÞÈκοØÖÆ£¬£¬£¬£¬£¬£¬£¬Ö»Òªurl¾ÙÐÐÁËbase64±àÂ룬£¬£¬£¬£¬£¬£¬½âÂëºó°üÀ¨jpg,jpeg,png,gifµÈÎļþºó׺¼´ÈÏ֤ͨ¹ý£¬£¬£¬£¬£¬£¬£¬Òò´ËÖ»Òª½á¹¹Îļþ·¾¶base64£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¼´¿ÉʵÏÖí§ÒâÎļþÏÂÔØ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_Godzilla¸ç˹À­_php_raw

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«¸ç˹À­webshellľÂí¡£¡£¡£¸ç˹À­ºÍ±ùЫһÑù£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖǿʢµÄwebshellÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬½ÓÄɼÓÃÜÁ÷Á¿¾ÙÐÐͨѶ¡£¡£¡£³£±»ºÚ¿ÍÓÃÀ´Î¬³ÖȨÏÞ£¬£¬£¬£¬£¬£¬£¬²¢¾ÙÐÐÏÂÒ»²½µÄÌáȨ»òÒÆ¶¯¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_NginxÆÊÎöÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ê¹ÓÃNginxÎļþÃûºó׺ÆÊÎö¹ýʧµÄÉÏ´«ÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_Netgear·ÓÉÆ÷ÏÂÁî×¢ÈëÎó²î[CNNVD-201612-432]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ê¹ÓÃNetgearÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_ÍøÂçÉãÏñÍ·_Avtech_CloudSetup.cgiÏÂÁî×¢ÈëÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÄ¿µÄIPµÄÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_Linksys_WRT110·ÓÉÆ÷_ÏÂÁî×¢ÈëÎó²î[CVE-2013-3568]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃLinksys WRT110·ÓÉÆ÷ÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

TCP_Java¶¯Ì¬Å²ÓÃ_java.lang.ProcessBuilder_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

TCP_Java¾²Ì¬Å²ÓÃ_java.lang.Runtime_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_WebShell_PHP_ÏÂÁîÖ´ÐÐGETÐÍÒ»¾ä»°ÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«PHPÏÂÁîÖ´ÐÐGETÐÍÒ»¾ä»°Ä¾Âí¡£¡£¡£Ê¹ÓÃsystem,exec,shell_exec,passthru,pcntl_exec,popen,proc_openº¯Êý¶Ô´«ÈëµÄget²ÎÊý¾ÙÐÐÖ´ÐУ¬£¬£¬£¬£¬£¬£¬µÖ´ï¿ØÖÆÐ§ÀÍÆ÷µÄÄ¿µÄ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_WebShell_PHP_ÏÂÁîÖ´ÐÐREQUESTÐÍÒ»¾ä»°ÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«PHPÏÂÁîÖ´ÐÐREQUESTÐÍÒ»¾ä»°Ä¾Âí¡£¡£¡£Ê¹ÓÃsystem,exec,shell_exec,passthru,pcntl_exec,popen,proc_openº¯Êý¶Ô´«ÈëµÄget,post,cookieµÈ²ÎÊý¾ÙÐÐÖ´ÐУ¬£¬£¬£¬£¬£¬£¬µÖ´ï¿ØÖÆÐ§ÀÍÆ÷µÄÄ¿µÄ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_WebShell_PHP_ÏÂÁîÖ´ÐÐPOSTÐÍÒ»¾ä»°ÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«PHPÏÂÁîÖ´ÐÐGETÐÍÒ»¾ä»°Ä¾Âí¡£¡£¡£Ê¹ÓÃsystem,exec,shell_exec,passthru,pcntl_exec,popen,proc_openº¯Êý¶Ô´«ÈëµÄpost²ÎÊý¾ÙÐÐÖ´ÐУ¬£¬£¬£¬£¬£¬£¬µÖ´ï¿ØÖÆÐ§ÀÍÆ÷µÄÄ¿µÄ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ZTE_ZXV10_H108L_Router_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZTE ZXV10 H108L RouterÊÇÖйúÖÐÐËͨѶ£¨ZTE£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£¡£¡£Ê¹ÓÃWIND Hellas°æ±¾¹Ì¼þµÄZXV10 H108L·ÓÉÆ÷Öб£´æÏµÍ³ÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃrootȨÏÞÖ´ÐÐϵͳÏÂÁî¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_phpunint_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-9841][CNNVD-201706-1127]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PHPUnit ÊÇ PHP ³ÌʽÓïÑÔÖÐ×î³£¼ûµÄµ¥Î»²âÊÔ (unit testing) ¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬Í¨³£phpunitʹÓÃcomposerºÜÊÇÊ¢ÐеÄPHPÒÀÀµÖÎÀíÆ÷¾ÙÐа²ÅÅ,½«»áÔÚÄ¿½ñĿ¼½¨ÉèÒ»¸övendorÎļþ¼Ð.phpunitÉú²úÇéÐÎÖÐÈÔÈ»×°ÖÃÁËËü,ÈôÊǸñàдÆ÷Ä£¿£¿£¿£¿£¿£¿£¿é±£´æÓÚWeb¿É»á¼ûĿ¼£¬£¬£¬£¬£¬£¬£¬Ôò±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208


ÊÂÎñÃû³Æ£º

HTTP_EnGenius_IoT_Cloud_Service_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_EnGenius_IoT_Cloud_Service_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201208