ÿÖÜÉý¼¶Í¨¸æ-2021-09-21
Ðû²¼Ê±¼ä 2021-09-22ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÎļþ»á¼û_³£¼ûÃüÃû |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé»á¼ûÄ¿µÄIPÖ÷»úÉϵĿÉÒÉÎļþµÄÐÐΪ¡£¡£¡£¡£¡£¡£´ËÊÂÎñ½ö¹©ÐÅÏ¢²Î¿¼£¬£¬£¬£¬²»´ú±íÕæÊµ¹¥»÷¡£¡£¡£¡£¡£¡£ÐèҪȷÈÏ»á¼ûµÄÎļþÔÚÄ¿µÄIPÖ÷»úÉÏÊÇ·ñÕæÊµ±£´æ¡£¡£¡£¡£¡£¡£ÇÒÐèҪȷÈÏÎļþÄÚÈÝÊÇ·ñΪ¶ñÒâÄÚÈÝ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_TP-Link_TL-WR940N_´úÂëÖ´ÐÐ[CVE-2019-6989][CNNVD-201904-442] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | TP-LinkTL-WR940NºÍTP-LinkTL-WR941ND¶¼ÊÇÖйúÆÕÁª£¨TP-Link£©µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£¡£¡£¡£¡£TP-LINKTL-WR940NºÍTL-WR941NDÖб£´æ»º³åÇø¹ýʧÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬£¬£¬£¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏߣ¬£¬£¬£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æÎ»ÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_Gh0st_Shine_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø³ÌÐò£¬£¬£¬£¬¹¦Ð§Ê®·Öǿʢ¡£¡£¡£¡£¡£¡£¾ßÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢½¨É衢ɾ³ý£©¡¢Àú³ÌÖÎÀí¡¢ÏµÍ³Ð§ÀÍ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢Éó²éÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§£¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Ç徲ɨÃè_ɨÃèÆ÷nessus |
Çå¾²ÀàÐÍ£º | Ç徲ɨÃè |
ÊÂÎñÐÎò£º | NessusÊÇÊ®·ÖǿʢµÄÎó²îɨÃèÆ÷£¬£¬£¬£¬¸Ã¹¤¾ß°üÀ¨×îеÄÎó²îÊý¾Ý¿â£¬£¬£¬£¬¼ì²âËÙÂʿ죬£¬£¬£¬×¼È·ÐԸߣ¬£¬£¬£¬ÊÇÉøÍ¸²âÊÔÖ÷Òª¹¤¾ßÖ®Ò»¡£¡£¡£¡£¡£¡£¸Ã¸æ¾¯ËµÃ÷¼ì²âµ½nessusɨÃèÆ÷ɨÃèÁ÷Á¿¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Optergy-Proton-Enterprise_ÏÂÁî×¢ÈëÎó²î[CVE-2019-7276][CNNVD-201906-284] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | OptergyProtonEnterpriseÊÇÃÀ¹úOptergy¹«Ë¾µÄÒ»ÌׯóÒµÐÞ½¨ÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£OptergyProtonEnterprise2.3.0a¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ±½Óµ¼º½µ½Î´±»¼Í¼µÄºóÞ籾£¬£¬£¬£¬»ñÈ¡ËùÓеÄϵͳ»á¼ûȨÏÞ£¬£¬£¬£¬½ø¶øÒÔ×î¸ßȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_rConfig_System_ajaxArchiveFiles.phpÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-19509][CNNVD-202001-144] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃrConfig_System_ajaxArchiveFiles.phpÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£¡£¡£rConfig3.9.3Öз¢Ã÷ÁËÒ»¸öÎÊÌâ¡£¡£¡£¡£¡£¡£Ô¶³ÌÈÏÖ¤Óû§¿ÉÒÔͨ¹ýÏòajaxArchiveFiles.php·¢ËÍGETÇëÇóÖ±½ÓÖ´ÐÐϵͳÏÂÁ£¬£¬£¬ÓÉÓÚpath²ÎÊýûÓйýÂ˾Íת´ï¸øexecº¯Êý£¬£¬£¬£¬Õâ»áµ¼ÖÂÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_D-Link-DIR-818LW&DIR-822_ÏÂÁî×¢Èë[CVE-2018-19986][CNNVD-201905-305] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | D-LinkDIR-822ºÍD-LinkDIR-818LW¶¼ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£¡£¡£¡£¡£D-LinkDIR-818LWRev.A2.05.B03ºÍDIR-822B1202KRb06Öеġ®RemotePort¡¯²ÎÊý±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬£¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÏÂÁîµÈ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Ãô¸ÐÎļþ»á¼û |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÄ¿µÄipÖ÷»úÖпÉÄÜ̻¶ÔÚÍâµÄÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210914 |
ÊÂÎñÃû³Æ£º | TCP_Java¶¯Ì¬Å²ÓÃ_java.lang.ProcessBuilder_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ÔÚJavaÖУ¬£¬£¬£¬³ÌÐò¿ª·¢Ö°Ô±Í¨³£»£»£»£»£»£»£»áͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨Ö´ÐÐÍⲿµÄShellÏÂÁî¡£¡£¡£¡£¡£¡£ProcessBuilderÊÇjava5.0ÒýÈëµÄ£¬£¬£¬£¬start()ÒªÁì·µ»ØProcessµÄÒ»¸öʵÀý¡£¡£¡£¡£¡£¡£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬£¬£¬£¬ÈôÊÇ´¦Öóͷ£ÍâÊÖÏÂÁîÖ´ÐÐʱ£¬£¬£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐÓõĹýÂË£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎó²îÔ¶³Ì×¢ÈëÏÂÁî»ò´úÂë²¢Ö´ÐС£¡£¡£¡£¡£¡£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÒ»¾±»Åû¶³ö±£´æJavaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬£¬½øÒ»²½ÍêÈ«¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210914 |
ÊÂÎñÃû³Æ£º | TCP_Java¾²Ì¬Å²ÓÃ_java.lang.Runtime_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ÔÚJavaÖУ¬£¬£¬£¬³ÌÐò¿ª·¢Ö°Ô±Í¨³£»£»£»£»£»£»£»áͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨Ö´ÐÐÍⲿµÄShellÏÂÁî¡£¡£¡£¡£¡£¡£RuntimeÀàÊÇJava³ÌÐòµÄÔËÐÐʱÇéÐΣ¬£¬£¬£¬¿ª·¢Õß¿ÉÒÔͨ¹ýgetRuntime()ÒªÁì»ñȡĿ½ñRuntimeÔËÐÐʱ¹¤¾ßµÄÒýÓᣡ£¡£¡£¡£¡£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬£¬£¬£¬ÈôÊÇ´¦Öóͷ£ÍâÊÖÏÂÁîÖ´ÐÐʱ£¬£¬£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐÓõĹýÂË£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎó²îÔ¶³Ì×¢ÈëÏÂÁî»ò´úÂë²¢Ö´ÐС£¡£¡£¡£¡£¡£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÒ»¾±»Åû¶³ö±£´æJavaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬£¬½øÒ»²½ÍêÈ«¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£¡£¡£¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_ÓÃÓÑNC_ÀúÊ·Îó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP¿ÉÄÜÕýÔÚʹÓÃÓÃÓÑNCµÄÎó²î¾ÙÐй¥»÷£»£»£»£»£»£»£»¹¥»÷Õßͨ¹ý½á¹¹ÓÃÓÑÌØ¶¨µÄ·ÓÉʵÏÖ´úÂëÖ´ÐС¢Îļþ¶ÁÈ¡µÈ²Ù×÷£»£»£»£»£»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬£¬£¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210921 |