ÿÖÜÉý¼¶Í¨¸æ-2022-07-08

Ðû²¼Ê±¼ä 2022-07-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Confluence_í§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2019-3396][CNNVD-201903-909]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ConfluenceÊÇ¿îÆóҵ֪ʶ¿âÈí¼þ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐConfluenceServerºÍDataCenter²úÆ·ÖÐʹÓõÄС¹¤¾ßÅþÁ¬Æ÷widgetconnecter×é¼þ£¨°æ±¾<=3.1.3£©Öб£´æí§ÒâÎļþ¶ÁÈ¡Îó²î

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_UCM6202_1.0.18.13Ô¶³ÌÏÂÁî×¢ÈëÎó²î[CVE-2020-5722][CNNVD-202003-1337]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

GrandstreamUCM6200ϵÁеÄHTTP½Ó¿ÚÈÝÒ×Êܵ½È«ÐÄÉè¼ÆµÄHTTPÇëÇóδ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌSQL×¢ÈëµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÒÔrootÉí·ÝÔÚ1.0.19.20֮ǰµÄ°æ±¾ÖÐÖ´ÐÐshellÏÂÁ£¬£¬»òÔÚ1.0.20.17֮ǰµÄ°æ±¾ÖеÄÃÜÂë»Ö¸´µç×ÓÓʼþÖÐ×¢ÈëHTML¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear_R7000_RouterÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

NetgearR7000,¹Ì¼þ°æ±¾1.0.7.2_1.1.93ÒÔ¼°¸üÔçÆÚ°æ±¾£¬£¬£¬R6400¹Ì¼þ°æ±¾1.0.1.6_1.0.4ÒÔ¼°¸üÔçÆÚ°æ±¾,°üÀ¨Ò»¸ö°üÀ¨í§ÒâÏÂÁî×¢ÈëÎó²î.¹¥»÷Õß¿ÉÄÜÓÕʹÓû§»á¼ûÇÉÈ«ÐÄ˼¹¹½¨µÄwebÕ¾µã£¬£¬£¬´Ó¶øÒÔ¸ùÓû§È¨ÏÞÔÚÊÜÓ°ÏìµÄ·ÓÉÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_shadowÄÚÈÝÎļþ»ØÏÔ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

·¢Ã÷ÓÐetc/shadowÎļþµÄ»ØÏÔÒ³Ãæ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£¡£¡£¡£¡£¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬£¬£¬ÔËÐк󣬣¬£¬¿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬£¬ÈçºóÃŵÈ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ʵÑéÅþÁ¬¿ó³Ø(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÍÚ¿óľÂíÊÔͼÅþÁ¬Ô¶³Ì¿ó³ØÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£¡£¡£¡£¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ·£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ·£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ÅþÁ¬¿ó³ØÀÖ³É(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÍÚ¿óľÂíÅþÁ¬Ô¶³Ì¿ó³ØÐ§ÀÍÆ÷ÀֳɵÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£¡£¡£¡£¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ·£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ·£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_»ñÈ¡ÍÚ¿óʹÃü(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½´Ó¿ó³ØÏò¿ó»úÏ·¢ÍÚ¿óʹÃüµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£¡£¡£¡£¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ·£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ·£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_CPUMiner_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_¿ó»úÉèÖù²ÏíÄ¿µÄ(BTC/LTC)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½¿ó»úÏò¿ó³ØÅú×¢¶Ô¹²ÏíÄ¿µÄµÄÆ«ºÃµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCPUMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£¡£CPUMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_H2database_console_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndiЧÀÍÆ÷µØµã¡£¡£¡£¡£¡£¡£¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ£¬£¬£¬½ÓÄÉjavaÓïÑÔ±àд£¬£¬£¬²»ÊÜÆ½Ì¨µÄÏÞÖÆ£¬£¬£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·ÖÀû±ãµÄweb¿ØÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£H2Database»¹Ìṩ¼æÈÝģʽ£¬£¬£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â£¬£¬£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿âºÜÊÇÀû±ã¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CMS_Joomla´úÂëÖ´ÐÐ[CVE-2020-10238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Joomla!ÊÇÃÀ¹úOpenSourceMattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£¡£¡£JoomlaÊÇÒ»Ì×ÄÚÈÝÖÎÀíϵͳ£¬£¬£¬ÊÇʹÓÃPHPÓïÑÔ¼ÓÉÏMYSQLÊý¾Ý¿âËù¿ª·¢µÄÈí¼þϵͳ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚjoomlaȨÏÞ·ÖÅɲ»¶ÔÀíµ¼ÖÂÖÎÀíԱȨÏÞÕ˺ſɶÔÏà¹ØphpÒ³Ãæ¾ÙÐб༭£¬£¬£¬²åÈëÏà¹Ø¶ñÒâ´úÂëµ¼ÖÂÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_HTTP_Server_·¾¶´©Ô½Îó²î[CVE-2021-42013][CNNVD-202110-413]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»úͨ¹ýApacheHTTPServer¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£Apache_HTTP_ServerÊÇApache»ù´¡¿ª·ÅµÄÊ¢ÐеÄHTTPЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Gogs_session_δÊÚȨ»á¼û[CVE-2018-18925][CNNVD-201811-049]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

gogsÊÇÒ»¿î¼«Ò״µÄ×ÔÖúGitЧÀÍÆ½Ì¨£¬£¬£¬¾ßÓÐÒ××°Öᢿçƽ̨¡¢ÇáÁ¿¼¶µÈÌØµã£¬£¬£¬Ê¹ÓÃÕßÖÚ¶à¡£¡£¡£¡£¡£¡£¡£Æä0.11.66¼°ÒÔǰ°æ±¾ÖУ¬£¬£¬£¨go-macaron/session¿â£©Ã»ÓжÔsessionid¾ÙÐÐУÑ飬£¬£¬¹¥»÷ÕßʹÓöñÒâsessionid¼´¿É¶ÁÈ¡í§ÒâÎļþ£¬£¬£¬Í¨¹ý¿ØÖÆÎļþÄÚÈÝÀ´¿ØÖÆsessionÄÚÈÝ£¬£¬£¬½ø¶øµÇ¼í§ÒâÕË»§¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÉϰ¶í§ÒâÕ˺ŰüÀ¨ÖÎÀíÔ±Õ˺Å£¬£¬£¬Í¬Ê±¿ÉʹÓÃgithooksÖ´ÐÐí§ÒâÏÂÁ£¬£¬Í¬Ê±±£´æÑÏÖØµÄԽȨºÍÏÂÁîÖ´ÐÐÎÊÌâ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SaltStack_δÊÚȨ»á¼û[CVE-2021-25281][CNNVD-202102-1696]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SaltAPIwheel_asyncδÊÚȨ»á¼ûÎó²îÖУ¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬Í¨¹ýwheel_asyncŲÓÃmasterµÄwheel²å¼þ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉÃô¸ÐÎļþÏÂÔØ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

·¢Ã÷Ãô¸ÐÎļþÏÂÔØÐÐΪ£¬£¬£¬ÈçÏÂÔØ±¸·ÝÎļþ£¬£¬£¬³ÌÐòÔ´Â룬£¬£¬SQLÎļþ£¬£¬£¬ÉèÖÃÎļþµÈÕâÀàÐÐΪ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉ¿ÉÖ´ÐÐÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»ú±£´æÉÏ´«¿ÉÒÉwebshellµ½Ä¿µÄipÖ÷»úµÄÐÐΪ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Java_ShellcodeÍâµØÀú³Ì×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWindowsVirtualMachineÀàÖеÄenqueueÒªÁì¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐJavaÍâµØÀú³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄpayload£¬£¬£¬Ê¹ÓöñÒâÀà¾ÙÐÐÀú³Ì×¢ÈëÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CouchDB_±ÊֱԽȨÎó²î[CVE-2017-12635][CNNVD-201711-487]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â£¬£¬£¬×¨×¢ÓÚÒ×ÓÃÐԺͳÉΪ¡±Íêȫӵ±§webµÄÊý¾Ý¿â¡±¡£¡£¡£¡£¡£¡£¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌ㬣¬£¬JavaScript×÷ΪÅÌÎÊÓïÑÔ£¬£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£µ¼ÖÂÎó²îµÄÔµ¹ÊÔ­ÓÉÊÇErlangºÍJavaScript£¬£¬£¬¶ÔJSONÆÊÎö·½·¨µÄ²î±ð£¬£¬£¬¹ØÓÚÖØ¸´µÄ¼üErlang»á´æ´¢Á½¸öÖµ£¬£¬£¬¶øJavaScriptÖ»´æ´¢µÚ¶þ¸öÖµ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Discuz!ML_V3.X_ÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Discuz!MLϵͳ¶ÔcookieÖÐÎüÊÕµÄlanguage²ÎÊýÄÚÈÝδ¹ýÂË£¬£¬£¬µ¼ÖÂ×Ö·û´®Æ´½Ó£¬£¬£¬´Ó¶øÖ´ÐÐphp´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_OpenSSL_·´µ¯shellÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐOpenSSL·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£¡£·´µ¯ÅþÁ¬£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀͶË£¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£¡£¡£¡£¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_CMS-Phpcms:V9.5.8_ºǫ́getshell

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCMS-Phpcms:V9.5.8ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬¸ÃÎó²îʹÓÃcontent.phpÎļþ½á¹¹¶ñÒâpayload£¬£¬£¬´Ó¶øÔì³É´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Covenant_ÅþÁ¬C2ЧÀÍÆ÷_ÉÏ´«ÐÅÏ¢»òÏÂÁî½»»¥

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

CovenantÊÇÒ»¸ö.NET¿ª·¢µÄC2(commandandcontrol)¿ò¼Ü£¬£¬£¬Ê¹ÓÃ.NETCoreµÄ¿ª·¢ÇéÐΣ¬£¬£¬²»µ«Ö§³ÖLinux£¬£¬£¬MacOSºÍWindows£¬£¬£¬»¹Ö§³ÖdockerÈÝÆ÷¡£¡£¡£¡£¡£¡£¡£CovenantÖ§³Ö¶¯Ì¬±àÒ룬£¬£¬Äܹ»½«ÊäÈëµÄC#´úÂëÉÏ´«ÖÁC2Server£¬£¬£¬»ñµÃ±àÒëºóµÄÎļþ²¢Ê¹ÓÃAssembly.Load()´ÓÄÚ´æ¾ÙÐмÓÔØ¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÅú×¢£¬£¬£¬CovenantµÄÌìÉúÎïGruntsľÂíºóÃÅÕýÔÚÅþÁ¬C2ЧÀÍÆ÷¾ÙÐÐÉÏ´«ÐÅÏ¢»òÏÂÁî½»»¥¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Alibaba-Canal-configÔÆÃÜÔ¿ÐÅϢй¶Îó²î

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

canalÊǰ¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌ⣬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄµØµã»á¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_laravel_pop3ʹÓÃÁ´¹¥»÷[CVE-2022-31279][CNNVD-202206-671]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Laravel9.1.8ÔÚ´¦Öóͷ£¹¥»÷Õß¿ØÖƵķ´ÐòÁл¯Êý¾Ýʱ£¬£¬£¬ÔÊÐíͨ¹ýIlluminate\Broadcasting\PendingBroadcast.phpÖеÄ__destructºÍFaker\Generator.phpÖеÄ__callÖеÄδÐòÁл¯µ¯³öÁ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖУ¬£¬£¬Ò»Ð©Ê¾ÀýDAGûÓÐ׼ȷÕûÀíÓû§ÌṩµÄ²ÎÊý£¬£¬£¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSÏÂÁî×¢ÈëµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.7.1ÒÔÏÂ_·ÇÊÚȨ»á¼û[CVE-2020-17523][CNNVD-202102-238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬ÊÚȨµÈ¡£¡£¡£¡£¡£¡£¡£¹ØÓÚApacheShiro1.7.1֮ǰµÄ°æ±¾£¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SangforEDR²»¸ßÓÚ3.2.19_·ÇÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÊÔͼͨ¹ýSangforEDRµÄ·ÇÊÚȨ»á¼ûÎó²î£¬£¬£¬ÊäÈëuser=admin¼´¿É»ñÈ¡Óû§È¨ÏÞ¡£¡£¡£¡£¡£¡£¡£SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÐÅ·þ¹«Ë¾ÌṩµÄÒ»Ì×ÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CLTPHP-v5.8_ºǫ́í§ÒâÎļþɾ³ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

CLTPHPÊÇ»ùÓÚThinkPHP5¿ª·¢£¬£¬£¬ºǫ́½ÓÄÉLayui¿ò¼ÜµÄÄÚÈÝÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¡£CLTPHP5.8¼°Ö®Ç°°æ±¾±£´æºǫ́í§ÒâÎļþɾ³ýÎó²î£¬£¬£¬Í¨¹ý½á¹¹¶ñÒâpayload¹¥»÷Õß¿Éɾ³ýϵͳÖеÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_AspectJWeaver_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃaspectjweaverµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁ˱£´æaspectjweaver:1.9.2,commons-collections:3.2.2µÄÒÀÀµ£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Gila-CMS-2.0.0_ÎļþдÈë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

GilaCMS2.0.0°æ±¾¼°ÒÔϰ汾»á½«User-AgentÖеÄÄÚÈÝдÈëµ½GSESSIONIDcookieÖÐÖ¸¶¨µÄÎļþÖУ¬£¬£¬Òò´Ë¿ÉÒÔʹÓÃÕâµã½«webshellдÈëµ½phpÎļþÖУ¬£¬£¬Ôì³Éí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_service.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚservice.phpÖжԴ«ÈëµÄservice_path²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_PrivManager.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚPrivManager.phpÖжԴ«ÈëµÄmode_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_SetVer.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚSetVer.phpÖжԴ«ÈëµÄversion_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_PHP-8.1.0-dev_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

PHP8.1.0-devÓÚ2021Äê3ÔÂ28ÈÕÐû²¼µÄ°æ±¾Öб£´æºóÃÅ£¬£¬£¬Í¨¹ýUser-AgenttÍ·¿ÉÒÔÖ´ÐÐí§Òâ´úÂë»òÏÂÁî

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring3_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSpring3µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËspring-tx:5.2.3.RELEASE,spring-context:5.2.3.RELEASE,javax.transaction-api:1.2£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JRMPListener_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJRMPListenerµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Ææ°²ÐÅÖÕ¶ËÇå¾²ÖÎÀíϵͳÌìÇæÔ½È¨»á¼ûÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓÃÌìÇæÇ°Ì¨Ö±½Ó»á¼ûĿ¼¿É»ñÈ¡Êý¾Ý¿âÏà¹ØÐÅÏ¢

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear-½»Á÷»ú_ÏÂÁî×¢Èë[CVE-2021-33514][CNNVD-202105-1401]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

×°±¸ÔÚÎüÊÕµ½setup.cgi?token=';$HTTP_USER_AGENT;'Ò»ÀàÊý¾ÝÊ£¬£¬£¬ÓÉÓÚδ¾ÙÐÐÇå¾²¹ýÂË£¬£¬£¬±£´æ±»¹¥»÷Õßͨ¹ý¾ÓÐĽṹµÄ¶ñÒâÊý¾Ý¹¥»÷£¬£¬£¬µ¼ÖÂÔÚ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Ãô¸ÐÐÅϢй¶_³£¼ûÃô¸ÐÎļþ»á¼û

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÄ¿µÄipÖ÷»úÖпÉÄÜ̻¶ÔÚÍâµÄÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Oracle_WebLogic_·´ÐòÁл¯Îó²î[CVE-2019-2725/CVE-2019-2729]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

´ËÎó²îÊÇÓÉÓÚÓ¦ÓÃÔÚ´¦Öóͷ£·´ÐòÁл¯ÊäÈëÐÅϢʱ±£´æÈ±ÏÝ£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÈ«ÐĽṹµÄ¶ñÒâHTTPÇëÇ󣬣¬£¬ÓÃÓÚ»ñµÃÄ¿µÄЧÀÍÆ÷µÄȨÏÞ£¬£¬£¬²¢ÔÚδÊÚȨµÄÇéÐÎÏÂÖ´ÐÐÔ¶³ÌÏÂÁ£¬£¬×îÖÕ»ñȡЧÀÍÆ÷µÄȨÏÞ¡£¡£¡£¡£¡£¡£¡£CVE-2019-2729ÊÇCVE-2019-2725µÄÈÆ¹ý¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_DolphinScheduler_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-11974][CNNVD-202012-1358]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApacheDolphinSchedulerµÄJDBC¿Í»§¶Ë¾ÙÐз´ÐòÁл¯²Ù×÷½ø¶øµ¼ÖÂÔ¶³Ì´úÖ´ÐС£¡£¡£¡£¡£¡£¡£ApacheDolphinScheduler(Incubator,Ô­EasyScheduler)ÊÇÒ»¸öÂþÑÜʽÊý¾ÝÊÂÇéÁ÷ʹÃüµ÷Àíϵͳ£¬£¬£¬Ö÷Òª½â¾öÊý¾ÝÑз¢ETL´í×ÛÖØ´óµÄÒÀÀµ¹ØÏµ£¬£¬£¬¶ø²»¿ÉÖ±¹Û¼à¿ØÊ¹Ãü¿µ½¡×´Ì¬µÈÎÊÌâ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Horde_Groupware_Webmail_Edition_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î[ZDI-20-1051]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

HordeGroupwareWebmailÊÇÃÀ¹úHorde¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷µÄÆóÒµ¼¶Í¨Ñ¶Ì×¼þ¡£¡£¡£¡£¡£¡£¡£HordeGroupwareWebmailÖб£´æ´úÂë×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷ÕßÔÚIMP_Prefs_SortÀàµÄ½á¹¹º¯ÊýÖжԲ»ÊÜÐÅÈεÄÊý¾ÝÎó²î¾ÙÐз´ÐòÁл¯¡£¡£¡£¡£¡£¡£¡£µÍÌØÈ¨µÄ¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µãÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MidaSolutionseFramework_ajaxreq.phpÏÂÁî×¢ÈëÎó²î[CVE-2020-15920][CNNVD-202007-1517]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

MidaSolutionsÊÇÒ»¼ÒרעÓÚͳһͨѶ(UC)µÄ¸ßÊÖÒÕÒâ´óÀû¹«Ë¾,MidaÍŶÓÒѳÉΪͳһЭ×÷ºÍרҵÏàͬµÄÈ«ÇòÏòµ¼Õß,ÏÕЩËùÓÐÐÐÒµµÄЧÀÍÌṩÉÌ£¬£¬£¬ÏµÍ³¼¯³ÉÉÌ¡£¡£¡£¡£¡£¡£¡£ÆäÏàÖúͬ°éÓÐ΢Èí,˼¿Æ,»ÝÆÕ,ÖйúµçÐŵÈ40¸öÌìÏÂ×ÅÃûÆóÒµ¡£¡£¡£¡£¡£¡£¡£MidaeFrameworkÊÇMidaSolutions¹«Ë¾ÆìÏÂÊÓÆµºÍÓïÒôÓ¦ÓóÌÐòµÄÍêÕûЧÀÍÌ×¼þ£¬£¬£¬ÓëÏÕЩËùÓÐÖ÷ÒªµÄUCƽ̨¼æÈÝ¡£¡£¡£¡£¡£¡£¡£¸ÃÌ×¼þ°üÀ¨»°ÎñÔ±¿ØÖÆÌ¨£¬£¬£¬¼Í¼Æ÷£¬£¬£¬´«ÕæÐ§ÀÍÆ÷£¬£¬£¬¼Æ·Ñ£¬£¬£¬ÐÐÁÐÖÎÀíÆ÷£¬£¬£¬×Ô¶¯»°ÎñÔ±£¬£¬£¬Òƶ¯Ó¦ÓóÌÐò£¬£¬£¬µç»°Ð§ÀÍ¡£¡£¡£¡£¡£¡£¡£MidaSolutionseFramework2.9.0¼°Ö®Ç°°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£Ëüʹδ¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷ÕßÄܹ»»ñµÃ¾ßÓÐÖÎÀí£¨root£©ÌØÈ¨µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¡£¡£¡£×¢ÈëµãλÓÚδ¹ûÕæµÄPHPÒ³ÃæÉÏ£¬£¬£¬¸ÃÒ³Ãæ¿ÉÒÔʹÓÃGET»òPOST¶ñÒâ¸ºÔØ×÷ΪĿµÄ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_SaltStack_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-16846/CVE-2020-25592][CNNVD-202011-302/CNNVD-202011-308]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÕýÔÚʹÓÃSaltStackµÄsalt-api½Ó¿ÚÖ´ÐÐí§ÒâÏÂÁ£»£»£»£»£»SaltStackÊÇÒ»¸öÂþÑÜʽÔËάϵͳ£¬£¬£¬ÔÚ»¥ÁªÍø³¡¾°Öб»ÆÕ±éÓ¦Ó㬣¬£¬ÓÐÒÔÏÂÁ½¸öÖ÷Òª¹¦Ð§£ºÉèÖÃÖÎÀíϵͳ£¬£¬£¬Äܹ»½«Ô¶³Ì½Úµãά»¤ÔÚÒ»¸öÔ¤½ç˵µÄ״̬£¨ÀýÈ磬£¬£¬È·±£×°ÖÃÌØ¶¨µÄÈí¼þ°ü²¢ÔËÐÐÌØ¶¨µÄЧÀÍ£©ÂþÑÜʽԶ³ÌÖ´ÐÐϵͳ£¬£¬£¬ÓÃÓÚÔÚÔ¶³Ì½ÚµãÉϵ¥¶À»òͨ¹ýí§ÒâÑ¡Ôñ±ê×¼À´Ö´ÐÐÏÂÁîºÍÅÌÎÊÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓÉÁ½¸ö×éºÏµÄCVEÎó²îµÄʹÓñ¬·¢£¬£¬£¬Í¨¹ýCVE-2020-25592½á¹¹í§Òâ¡°eauth¡±/¡°token¡±Öµ£¬£¬£¬ÈƹýÉí·ÝÈÏÖ¤£»£»£»£»£»£»Í¨¹ýCVE-2020-16846Ö´ÐÐshell¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_SQL_Server_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0618][CNNVD-202002-496]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS)£¬£¬£¬ÊÇÏÖÔÚÌìÏÂÉÏÆÕ±éʹÓõÄÊý¾Ý¿âÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬣¬£¬¿ÉʹÓôËÎó²îÔÚ±¨±íЧÀÍÆ÷ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_PHP·´ÐòÁл¯¹¤Ç©×ÖÌÃÊý¾Ý·¢Ã÷

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

Èô³ÌÐòδ¶ÔÓû§ÊäÈëµÄÐòÁл¯×Ö·û´®¾ÙÐмì²â£¬£¬£¬Ôò¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔ¿ØÖÆ·´ÐòÁл¯Àú³Ì£¬£¬£¬Í¨¹ýÔÚ²ÎÊýÖÐ×¢ÈëһЩ´úÂ룬£¬£¬´Ó¶øµÖ´ï´úÂëÖ´ÐУ¬£¬£¬SQL×¢È룬£¬£¬Ä¿Â¼±éÀúµÈ²»¿É¿ØÐ§¹û¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708