ÿÖÜÉý¼¶Í¨¸æ-2022-03-15

Ðû²¼Ê±¼ä 2022-03-15

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_ÈÕÖ¾ÎļþÐÅϢй¶

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÐÅϢй¶Îó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ £¬£¬£¬£¬£¬£¬¿É¶ÁȡĿµÄIPÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢Îļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆÆ½âʹÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÏÖÔÚÖ÷»úÕýÊܵ½ApachShiroRememberme²ÎÊýÏÂÁî×¢Èë´úÂëÖ´Ðй¥»÷ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬£¬£¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£¿ËÈÕ £¬£¬£¬£¬£¬£¬·¢Ã÷Õë¶Ô¸ÃÎó²îµÄʹÓ÷½·¨Òѱ»Ð¡¹æÄ£Èö²¥£¨Îó²î°æ±¾<=1.2.4£© £¬£¬£¬£¬£¬£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¶Ô´ËÎó²î¾ÙÐзÀ»¤¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÏÖÔÚÖ÷»úÕýÊܵ½ApachShiroRememberme²ÎÊýÏÂÁî×¢Èë´úÂëÖ´Ðй¥»÷ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬£¬£¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£¿ËÈÕ £¬£¬£¬£¬£¬£¬·¢Ã÷Õë¶Ô¸ÃÎó²îµÄʹÓ÷½·¨Òѱ»Ð¡¹æÄ£Èö²¥£¨Îó²î°æ±¾<=1.2.4£© £¬£¬£¬£¬£¬£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¶Ô´ËÎó²î¾ÙÐзÀ»¤¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.Torchwood_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅTorchwood¡£¡£¡£¡£¡£¡£TorchwoodÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ £¬£¬£¬£¬£¬£¬ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£Ö÷Ҫͨ¹ýCHMÎļþÈö²¥¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_LinuxÏÂÁîÖ´ÐлØÏÔ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»ú·ºÆðÁËijЩLinuxÏÂÁÈçw¡¢top¡¢uptimeµÈ£©Ö´ÐеĻØÏÔÁ÷Á¿ £¬£¬£¬£¬£¬£¬°üÀ¨Ä¿½ñϵͳʱ¿Ì¡¢ÔËÐÐʱ¼ä¡¢Óû§×ÜÅþÁ¬Êý¡¢Æ½¾ù¸ºÔصÈÐÅÏ¢

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_ElasticSearch_Ŀ¼´©Ô½Îó²î[CVE-2015-5531]

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃElasticSearchĿ¼´©Ô½Îó²î¾ÙÐй¥»÷µÄÐÐΪ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷ЧÀÍÆ÷ £¬£¬£¬£¬£¬£¬»ùÓÚJava¿ª·¢¡£¡£¡£¡£¡£¡£ElasticSearch±£´æÄ¿Â¼´©Ô½Îó²î £¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓøÃÎó²î¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_elasticsearch-head_Ŀ¼´©Ô½Îó²î[CVE-2015-3337]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃElasticSearchhead²å¼þĿ¼´©Ô½Îó²î¾ÙÐй¥»÷µÄÐÐΪ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²î¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷ЧÀÍÆ÷ £¬£¬£¬£¬£¬£¬»ùÓÚJava¿ª·¢¡£¡£¡£¡£¡£¡£ElasticSearchhead²å¼þ±£´æÄ¿Â¼´©Ô½Îó²î £¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓøÃÎó²î¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Apache_Solr_SSRFÎó²î[CVE-2021-27905]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

ApacheSolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷ЧÀÍ £¬£¬£¬£¬£¬£¬Ê¹ÓÃJava±àд¡¢ÔËÐÐÔÚServletÈÝÆ÷µÄÒ»¸ö×ÔÁ¦µÄÈ«ÎÄËÑË÷ЧÀÍÆ÷ £¬£¬£¬£¬£¬£¬ÊÇApacheLuceneÏîÄ¿µÄ¿ªÔ´ÆóÒµËÑË÷ƽ̨¡£¡£¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚûÓжÔÊäÈëµÄÄÚÈݾÙÐÐУÑé £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚδÊÚȨµÄÇéÐÎÏ £¬£¬£¬£¬£¬£¬½á¹¹¶ñÒâÊý¾ÝÖ´ÐÐSSRF¹¥»÷ £¬£¬£¬£¬£¬£¬×îÖÕÔì³Éí§Òâ¶ÁȡЧÀÍÆ÷ÉϵÄÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_java·´ÐòÁл¯_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIP·¢ËÍ¿ÉÄܱ£´æÔ¶³ÌÏÂÁîÖ´ÐÐŲÓõÄjava·´ÐòÁл¯ÇëÇ󡣡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_POSCMS_í§ÒâÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

POSCMS3.2.0°æ±¾Ç°Ì¨½çÃæ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£Ìض¨Â·¾¶´«Èë¶ñÒâ²ÎÊý £¬£¬£¬£¬£¬£¬»áµ¼Ö´úÂëÖ´ÐÐ £¬£¬£¬£¬£¬£¬µ¼Ö¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²îдÈë¶ñÒâ´úÂë £¬£¬£¬£¬£¬£¬²¢¿ÉÒÔͨ¹ý´ËÎó²î¾ÙÐÐgetshell

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_POSCMS_Îļþ°üÀ¨

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

POSCMS3.2.0°æ±¾ºǫ́ÖÎÀí½çÃæµÄ¸½¼þÉÏ´«¹¦Ð§Ö»ÊǶÔÎļþºó׺¾ÙÐÐÁËÑéÖ¤ £¬£¬£¬£¬£¬£¬µ«²¢Ã»ÓжÔÎļþÄÚÈݾÙÐÐÑéÖ¤ £¬£¬£¬£¬£¬£¬µ¼Ö¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²îÉÏ´«¶ñÒâÎļþ £¬£¬£¬£¬£¬£¬²¢¿ÉÒÔͨ¹ýʹÓôËÎļþ¾ÙÐÐgetshell¡£¡£¡£¡£¡£¡£ÒªÖ´Ðй¥»÷ £¬£¬£¬£¬£¬£¬ÐèÒªÄܹ»µÇ¼µ½ºǫ́ÖÎÀí½çÃæ £¬£¬£¬£¬£¬£¬ÇÒÓÐÉÏ´«ÎļþµÄȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_mini_httpd_í§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2018-18778][CNNVD-201810-1382]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Mini_httpdÊÇÒ»¸ö΢Ð͵ÄHttpЧÀÍÆ÷ £¬£¬£¬£¬£¬£¬ÔÚÕ¼ÓÃϵͳ×ÊÔ´½ÏСµÄÇéÐÎÏ¿ÉÒÔ¼á³ÖÒ»¶¨Ë®Æ½µÄÐÔÄÜ£¨Ô¼ÎªApacheµÄ90%£© £¬£¬£¬£¬£¬£¬Òò´ËÆÕ±é±»ÖÖÖÖIOT£¨Â·ÓÉÆ÷ £¬£¬£¬£¬£¬£¬½»Á÷Æ÷ £¬£¬£¬£¬£¬£¬ÉãÏñÍ·µÈ£©×÷ΪǶÈëʽЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¶ø°üÀ¨»ªÎª £¬£¬£¬£¬£¬£¬zyxel £¬£¬£¬£¬£¬£¬º£¿£¿£¿£¿£¿£¿µÍþÊÓ £¬£¬£¬£¬£¬£¬Ê÷Ý®ÅɵÈÔÚÄڵij§ÉÌµÄÆìÏÂ×°±¸¶¼Ôø½ÓÄÉMini_httpd×é¼þ¡£¡£¡£¡£¡£¡£ACMEmini_httpd<1.30°æ±¾±£´æÒ»¸öí§ÒâÎļþ¶ÁÈ¡Îó²î £¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÔÚmini_httpd¿ªÆôÐéÄâÖ÷»úģʽµÄÇéÐÎÏ £¬£¬£¬£¬£¬£¬Óû§ÇëÇóhttp://HOST/FILE½«»á»á¼ûµ½Ä¿½ñĿ¼ÏµÄHOST/FILEÎļþ £¬£¬£¬£¬£¬£¬¶øµ±HOSTΪ¿Õ¡¢FILE=etc/passwdµÄʱ¼ä £¬£¬£¬£¬£¬£¬ÉÏÊöÓï¾äЧ¹ûΪ/etc/passwd¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿É×÷Ϊ¾ø¶Ô·¾¶ £¬£¬£¬£¬£¬£¬¶ÁÈ¡µ½ÁË/etc/passwd £¬£¬£¬£¬£¬£¬Ôì³Éí§ÒâÎļþ¶ÁÈ¡Îó²î¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_Technology·ÓÉÆ÷_δÊÚȨÏÂÁî×¢Èë[CVE-2022-25134][CNNVD-202202-1645]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýCVE-2022-25134Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£TOTOLINKTechnology·ÓÉÆ÷¹Ì¼þÀï±£´æÏÂÁî×¢ÈëÎó²î £¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì·ÓÉÆ÷Ðͺż°Æä¹Ì¼þ°æ±¾Îª£ºA830R(V5.9c.4729_B20191112)¡¢3100R(V4.1.2cu.5050_B20200504)¡¢A950RG(V4.1.2cu.5161_B20200903)¡¢A800R(V4.1.2cu.5137_B20200730)¡¢A3000RU(V5.9c.5185_B20201128)¡¢A810R(V4.1.2cu.5182_B20201026)¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÏÖÔÚÖ÷»úÕýÊܵ½ApachShiroRememberme²ÎÊýÏÂÁî×¢Èë´úÂëÖ´Ðй¥»÷ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬£¬£¬£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£¿ËÈÕ £¬£¬£¬£¬£¬£¬·¢Ã÷Õë¶Ô¸ÃÎó²îµÄʹÓ÷½·¨Òѱ»Ð¡¹æÄ£Èö²¥£¨Îó²î°æ±¾<=1.2.4£© £¬£¬£¬£¬£¬£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¶Ô´ËÎó²î¾ÙÐзÀ»¤¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_EX200ÎÞÏßÖÐ¼ÌÆ÷_δÊÚȨÏÂÁî×¢Èë[CVE-2021-43711][CNNVD-202201-147]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ToTolinkEx200ÊÇÖйúToTolink¹«Ë¾µÄÒ»¿î2.4GÎÞÏßÖÐ¼ÌÆ÷ £¬£¬£¬£¬£¬£¬Ö¼ÔÚÀ©´óÏÖÓÐWi-FiÍøÂçµÄÁýÕÖ¹æÄ£¡£¡£¡£¡£¡£¡£ToTolinkEx200¶ÔhttpGET²ÎÊý´¦Öóͷ£²»µ± £¬£¬£¬£¬£¬£¬±£´æÏÂÁî×¢ÈëÎó²î £¬£¬£¬£¬£¬£¬µ¼ÖÂδÊÚȨԶ³ÌÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²î×¢ÈëÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÃûÌÃ×Ö·û´®

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â £¬£¬£¬£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãÄÚÖÃlookupÃûÌõÄ×Ö·û´® £¬£¬£¬£¬£¬£¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê± £¬£¬£¬£¬£¬£¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§¡£¡£¡£¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬£¬£¬£¬£¬£¬´ËÐÐΪ¾ßÓÐÒ»¶¨Î£º¦ £¬£¬£¬£¬£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬£¬£¬£¬£¬£¬ÈçÈÆ¹ýWAF¼ì²â £¬£¬£¬£¬£¬£¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÃûÌÃ×Ö·û´®

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â £¬£¬£¬£¬£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷¡£¡£¡£¡£¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãÄÚÖÃlookupÃûÌõÄ×Ö·û´® £¬£¬£¬£¬£¬£¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê± £¬£¬£¬£¬£¬£¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§¡£¡£¡£¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬£¬£¬£¬£¬£¬´ËÐÐΪ¾ßÓÐÒ»¶¨Î£º¦ £¬£¬£¬£¬£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬£¬£¬£¬£¬£¬ÈçÈÆ¹ýWAF¼ì²â £¬£¬£¬£¬£¬£¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315

 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ £¬£¬£¬£¬£¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð £¬£¬£¬£¬£¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£¡£¡£¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò £¬£¬£¬£¬£¬£¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£¡£¡£¡£¡£¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿ £¬£¬£¬£¬£¬£¬ÒÔÊÇÐèÒªÖØµã¹Ø×¢¡£¡£¡£¡£¡£¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220315