ÿÖÜÉý¼¶Í¨¸æ-2022-11-01

Ðû²¼Ê±¼ä 2022-11-01
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_drag-and-drop-multiple-file-uploader_ÎļþÉÏ´«[CVE-2020-12800][CNNVD-202006-519]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWordPressdraganddropmultiplefileuploader²å¼þ1.3.3.3֮ǰ°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£¡£¡£DragandDropMultipleFileUploaderÊÇContactForm7µÄÒ»¸ö¼òÆÓ¡¢Ö±½ÓµÄWordPress²å¼þÀ©Õ¹£¬£¬£¬£¬£¬£¬£¬ËüÔÊÐíÓû§Ê¹ÓÃÍϷŹ¦Ð§»òWeb±íµ¥µÄͨÓÃä¯ÀÀÎļþÉÏ´«¶à¸öÎļþ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_vTiger_CRM_ÎļþÉÏ´«[CVE-2013-3591][CNNVD-201310-746]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃvTigerCRM5.3.0ÒÔ¼°5.4.0°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔÚÉϰ¶ºó»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£¡£¡£VtigerCRMÊÇÃÀ¹úVtiger¹«Ë¾µÄÒ»Ì×»ùÓÚSugarCRM¿ª·¢µÄ¿Í»§¹ØÏµÖÎÀíϵͳ£¨CRM£©£¬£¬£¬£¬£¬£¬£¬ËüÌṩÖÎÀí¡¢ÍøÂç¡¢ÆÊÎö¿Í»§ÐÅÏ¢µÈ¹¦Ð§

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Sophos_Firewall_´úÂëÖ´ÐÐ[CVE-2022-3236]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSophosFirewallv19.0MR1(19.0.1)ÒÔ¼°Ö®Ç°°æ±¾Öб£´æµÄ´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬´Ó¶øÄ¿µÄϵͳȨÏÞ¡£¡£¡£¡£¡£SophosXGFirewallÊÇSophos¹«Ë¾Äܹ»Íêȫʶ±ðÍøÂçÉϱ»Ñ¬È¾µÄÓû§£¬£¬£¬£¬£¬£¬£¬²¢×Ô¶¯ÏÞÖÆ¶ÔÆäËûÍøÂç×ÊÔ´µÄ»á¼ûµÄÍøÂçÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢_E-office10ǰ̨_í§ÒâÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚͨ¹ý·ºÎ¢_E-office10ǰ̨µÄOfficeServer.phpÒ³ÃæÉÏ´«í§ÒâÎļþ£»£»£»Í¨¹ý´ËÎó²î¹¥»÷Õß¿ÉÉÏ´«í§ÒâÃûÌõÄÎļþ£¬£¬£¬£¬£¬£¬£¬ºó¶ËЧÀÍÆ÷»áÀֳɯÊÎö¸ÃÎļþ£¬£¬£¬£¬£¬£¬£¬µ¼Ö¿Éͨ¹ý´ËÎó²îÖ±½Ó»ñȡϵͳȨÏÞ¡£¡£¡£¡£¡£·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬£¬£¬£¬£¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬£¬£¬£¬£¬£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬣¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬£¬£¬£¬£¬£¬£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬£¬£¬£¬£¬£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101