ÿÖÜÉý¼¶Í¨¸æ-2022-08-23

Ðû²¼Ê±¼ä 2022-08-23
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Òç³ö¹¥»÷_GPON·ÓÉÆ÷_ÈÏÖ¤Õ»Òç³öCVE-2019-3921][CNNVD-201903-081]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_GPON_·ÓÉÆ÷_ÈÏÖ¤Õ»Òç³öÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SonicWall_Global_Management_System_í§Òâ´úÂëÖ´ÐÐ[CVE-2018-9866][CNNVD-201808-124]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCVE-2018-9866Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£SonicWallGlobalManagementSystem£¨GMS£©ÊÇ¿ìËÙ°²Åźͼ¯ÖÐÖÎÀíDellSonicWALL·À»ðǽ¡¢·´À¬»øÓʼþ¡¢±¸·ÝºÍ»Ö¸´ÒÔ¼°Çå¾²Ô¶³Ì»á¿´·¨¾ö¼Æ»®µÄÒ»Ì×ÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¡£SonicWallGMS8.1¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐÑéÖ¤Óû§Ìá½»µÄÓÃÓÚXML-RPCŲÓõIJÎÊý¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_Òç³ö¹¥»÷_HelixServer_DESCRIBEÇëÇóÔ¶³Ì¶ÑÒç³ö[CVE-2006-6026]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHelixServerDESCRIBEÇëÇóÔ¶³Ì¶ÑÒç³öÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£HelixServerÊÇRMýÌåÁ÷ЧÀÍÆ÷REALµÄ¿ªÔ´°æ±¾£¬£¬£¬£¬£¬£¬£¬Ö§³ÖRTSPЭÒ飬£¬£¬£¬£¬£¬£¬Ö§³ÖRM¡¢MP3µÈÃûÌᣡ£¡£¡£¡£¡£¡£HelixServer¿ÉÒÔ¹¹½¨¸ßÐÔÄܵÄÁ÷ýÌåЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Ö§³Ö¶àÃûÌᢿçƽ̨£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ½«¸ßÖÊÁ¿µÄ¶àýÌåÄÚÈÝ·¢µ½ÈκÎÍøÂçÄܹ»´¥¼°µÄµØ·½¡£¡£¡£¡£¡£¡£¡£Ö§³ÖÒÆ¶¯´«Êä±ê×¼£¬£¬£¬£¬£¬£¬£¬°üÀ¨3GPPʵʱѹËõ£¬£¬£¬£¬£¬£¬£¬Öª×ãÓû§µÄ²î±ðµÄЧÀÍÐèÇ󡣡£¡£¡£¡£¡£¡£RealNetworksHelixServerºÍHelixMobileServer11.1.3֮ǰµÄ°æ±¾£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°HelixDNAServer11.0ºÍ11.1Öб£´æ»ùÓڶѵĻº³åÇøÒç³ö£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý°üÀ¨ÎÞЧLoadTestPassword×ֶεÄÐÎòÇëÇóÔì³É¾Ü¾øÐ§ÀÍ£¨Ó¦ÓóÌÐòÍ߽⣩»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_ÆäËü×¢Èë_Courier_IMAP_4.0.1_XMAILDIR±äÁ¿Ô¶³ÌShellÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCourierIMAPXMAILDIR±äÁ¿Ô¶³ÌShellÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£Courier-IMAPÊÇCourierÓʼþϵͳÖеÄIMAPЧÀͳÌÐò¡£¡£¡£¡£¡£¡£¡£Courier-IMAP¶Ô±äÁ¿Êý¾ÝµÄ¹ýÂËÉϱ£´æÎó²î£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÔÚЧÀÍÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_Òç³ö¹¥»÷_CA_BrightStor_ARCserve_BackupЧÀÍÔ¶³Ì»º³åÇøÒç³ö[CVE-2006-6076]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCABrightStorARCserveBackupЧÀÍÔ¶³Ì»º³åÇøÒç³öÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£CABrightStorARCserveBackup11.5ÒÔ¼°¸üÔç°æ±¾ÖеÄTapeEngine±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý¶ÔTCP¶Ë¿Ú6502µÄijЩRPCÇëÇóÀ´Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ÖÂÔ¶OA_E-Bridge_saveYZJFile_í§ÒâÎļþ¶ÁÈ¡

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

δÊÚȨí§ÒâÎļþ¶ÁÈ¡,/wxjsapi/saveYZJFile½Ó¿Ú»ñÈ¡filepath,ÊäÈëÎļþ·¾¶->¶ÁÈ¡ÎļþÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£·µ»ØÊý¾Ý°üÄÚ·ºÆðÁ˳ÌÐòµÄ¾ø¶Ô·¾¶,¹¥»÷Õß¿ÉÒÔͨ¹ý·µ»ØÄÚÈÝʶ±ð³ÌÐòÔËÐз¾¶´Ó¶øÏÂÔØÊý¾Ý¿âÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Free-IPA_XXE×¢Èë[CVE-2022-2414][CNNVD-202207-2780]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

FreeIPAÊÇÃâ·ÑµÄ¿ªÔ´Éí·ÝÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬£¬Æäv11.2.0-beta3ǰµÄ°æ±¾±£´æXMLʵÌå×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Äܹ»Ê¹ÓøÃÎó²î¶ÁȡĿµÄЧÀÍÆ÷Îļþ£¬£¬£¬£¬£¬£¬£¬¶Ë¿Ú̽²âµÈ²Ù×÷

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_±©Á¦²Â½â_HikvisionDVRDS-7204HGHI_±©Á¦²Â½â[CVE-2020-7057][CNNVD-202001-467]

Çå¾²ÀàÐÍ£º

Çî¾Ù̽²â

ÊÂÎñÐÎò£º

HikvisionDVRDS-7204HGHIV4.0.1build°æ±¾±£´æÓû§Ã¶¾ÙÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·µ»Ø°üÅжÏÓû§ÊÇ·ñ±£´æ

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SonicWall-SSL-VPN_jarrewrite.sh_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SonicWallSSL-VPN²úÆ·ÖÐʹÓÃÁ˼«ÎªÀϾɵÄLinuxÄں˺ÍHTTPCGI¿ÉÖ´ÐгÌÐò£¬£¬£¬£¬£¬£¬£¬¸Ã³ÌÐòÔÚ´¦Öóͷ£httpÇëÇóʱ£¬£¬£¬£¬£¬£¬£¬ÎÞ·¨×¼È·µÄÆÊÎöhttpheader¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îµ¼ÖÂÏÂÁî×¢È룬£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õßͨ¹ý×¢ÈëÏÂÁî¿ÉÒÔÇáËɵĻñµÃnobodyÓû§È¨Ï޵ĿØÖÆÈ¨ÏÞ¡£¡£¡£¡£¡£¡£¡£Í¬Ê±ÓÉÓÚÀϾÉÄں˵ÄÎÊÌâÒÔ¼°ÆäÖб£´æÎó²îµÄ¿ÉÖ´ÐгÌÐò£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÈÝÒ×µÄÌáÉýȨÏÞ²¢ÍêÈ«½ÓÊܸÃЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Webmin-Software-Package-Updates_ÏÂÁîÖ´ÐÐ[CVE-2022-36446]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

WebminÊÇUnixϵͳÖÎÀíWeb½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬Í¨¹ýÈÎÒ»ä¯ÀÀÆ÷¶¼¿ÉÉèÖÃÓû§ÕË»§¡¢Apache¡¢DNS¡¢DNS¡¢Îļþ¹²Ïí¼°ÆäËû¡£¡£¡£¡£¡£¡£¡£Webmin1.998ÒÔǰµÄ°æ±¾µÄ/package-updates/update.cgiÔÚÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£¡£¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_Ô¶³Ì¿ØÖÆÈí¼þ_·¢Ã÷ToDeskʹÓÃ

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚʹÓÃToDesk¡£¡£¡£¡£¡£¡£¡£ToDeskÊÇÒ»¿î¶àƽ̨Զ³Ì¿ØÖÆ/Ô¶³ÌЭÖúÈí¼þ£¬£¬£¬£¬£¬£¬£¬Ö÷´òÁ÷ͨÒÔ¼°Ð¡ÎÒ˽¼ÒÃâ·ÑµÄÌØµã¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

TCP_ľÂí_PSW.OnlineGames_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£¡£¡£Trojan.PSW.OnlineGamesÊÇÒ»¸öÍøÓεÁºÅľÂí£¬£¬£¬£¬£¬£¬£¬ÍµÈ¡ÍøÓÎDNFµÄÕ˺ÅÃÜÂë·¢Ë͵½ºÚ¿ÍЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£ÍµÈ¡ÍøÓÎDNFµÄÕ˺ÅÃÜÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_µÇ¼ÀÖ³É

Çå¾²ÀàÐÍ£º

ųÈõ¿ÚÁî

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÀֳɵǼµ½Ä¿µÄIPµØµãÖ÷»úµÄÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÊÇÕý³£µÄÍøÂçÐÐΪ£¬£¬£¬£¬£¬£¬£¬Ò»Ñùƽ³£Ã»ÓÐΣº¦¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£¡£¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220823