ÿÖÜÉý¼¶Í¨¸æ-2022-07-08

Ðû²¼Ê±¼ä 2022-07-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Confluence_í§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2019-3396][CNNVD-201903-909]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ConfluenceÊÇ¿îÆóҵ֪ʶ¿âÈí¼þ¡£¡£¡£¡£¡£¡£ÆäÖÐConfluenceServerºÍDataCenter²úÆ·ÖÐʹÓõÄС¹¤¾ßÅþÁ¬Æ÷widgetconnecter×é¼þ£¨°æ±¾<=3.1.3£©Öб£´æí§ÒâÎļþ¶ÁÈ¡Îó²î

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_UCM6202_1.0.18.13Ô¶³ÌÏÂÁî×¢ÈëÎó²î[CVE-2020-5722][CNNVD-202003-1337]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

GrandstreamUCM6200ϵÁеÄHTTP½Ó¿ÚÈÝÒ×Êܵ½È«ÐÄÉè¼ÆµÄHTTPÇëÇóδ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌSQL×¢ÈëµÄ¹¥»÷¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÒÔrootÉí·ÝÔÚ1.0.19.20֮ǰµÄ°æ±¾ÖÐÖ´ÐÐshellÏÂÁ£¬£¬£¬£¬£¬»òÔÚ1.0.20.17֮ǰµÄ°æ±¾ÖеÄÃÜÂë»Ö¸´µç×ÓÓʼþÖÐ×¢ÈëHTML¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear_R7000_RouterÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

NetgearR7000,¹Ì¼þ°æ±¾1.0.7.2_1.1.93ÒÔ¼°¸üÔçÆÚ°æ±¾£¬£¬£¬£¬£¬£¬R6400¹Ì¼þ°æ±¾1.0.1.6_1.0.4ÒÔ¼°¸üÔçÆÚ°æ±¾,°üÀ¨Ò»¸ö°üÀ¨í§ÒâÏÂÁî×¢ÈëÎó²î.¹¥»÷Õß¿ÉÄÜÓÕʹÓû§»á¼ûÇÉÈ«ÐÄ˼¹¹½¨µÄwebÕ¾µã£¬£¬£¬£¬£¬£¬´Ó¶øÒÔ¸ùÓû§È¨ÏÞÔÚÊÜÓ°ÏìµÄ·ÓÉÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_shadowÄÚÈÝÎļþ»ØÏÔ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

·¢Ã÷ÓÐetc/shadowÎļþµÄ»ØÏÔÒ³Ãæ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£¡£¡£¡£¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬¿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬£¬£¬£¬£¬ÈçºóÃŵÈ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ʵÑéÅþÁ¬¿ó³Ø(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÍÚ¿óľÂíÊÔͼÅþÁ¬Ô¶³Ì¿ó³ØÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£¡£¡£¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ·£¬£¬£¬£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ·£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ÅþÁ¬¿ó³ØÀÖ³É(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÍÚ¿óľÂíÅþÁ¬Ô¶³Ì¿ó³ØÐ§ÀÍÆ÷ÀֳɵÄÐÐΪ¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£¡£¡£¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ·£¬£¬£¬£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ·£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_»ñÈ¡ÍÚ¿óʹÃü(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½´Ó¿ó³ØÏò¿ó»úÏ·¢ÍÚ¿óʹÃüµÄÐÐΪ¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£¡£¡£¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ·£¬£¬£¬£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ·£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_CPUMiner_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_¿ó»úÉèÖù²ÏíÄ¿µÄ(BTC/LTC)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½¿ó»úÏò¿ó³ØÅú×¢¶Ô¹²ÏíÄ¿µÄµÄÆ«ºÃµÄÐÐΪ¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCPUMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£CPUMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_H2database_console_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndiЧÀÍÆ÷µØµã¡£¡£¡£¡£¡£¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ£¬£¬£¬£¬£¬£¬½ÓÄÉjavaÓïÑÔ±àд£¬£¬£¬£¬£¬£¬²»ÊÜÆ½Ì¨µÄÏÞÖÆ£¬£¬£¬£¬£¬£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·ÖÀû±ãµÄweb¿ØÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£¡£¡£¡£¡£¡£H2Database»¹Ìṩ¼æÈÝģʽ£¬£¬£¬£¬£¬£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â£¬£¬£¬£¬£¬£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿âºÜÊÇÀû±ã¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CMS_Joomla´úÂëÖ´ÐÐ[CVE-2020-10238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Joomla!ÊÇÃÀ¹úOpenSourceMattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£¡£JoomlaÊÇÒ»Ì×ÄÚÈÝÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬ÊÇʹÓÃPHPÓïÑÔ¼ÓÉÏMYSQLÊý¾Ý¿âËù¿ª·¢µÄÈí¼þϵͳ¡£¡£¡£¡£¡£¡£ÓÉÓÚjoomlaȨÏÞ·ÖÅɲ»¶ÔÀíµ¼ÖÂÖÎÀíԱȨÏÞÕ˺ſɶÔÏà¹ØphpÒ³Ãæ¾ÙÐб༭£¬£¬£¬£¬£¬£¬²åÈëÏà¹Ø¶ñÒâ´úÂëµ¼ÖÂÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_HTTP_Server_·¾¶´©Ô½Îó²î[CVE-2021-42013][CNNVD-202110-413]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»úͨ¹ýApacheHTTPServer¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£¡£¡£Apache_HTTP_ServerÊÇApache»ù´¡¿ª·ÅµÄÊ¢ÐеÄHTTPЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Gogs_session_δÊÚȨ»á¼û[CVE-2018-18925][CNNVD-201811-049]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

gogsÊÇÒ»¿î¼«Ò״µÄ×ÔÖúGitЧÀÍÆ½Ì¨£¬£¬£¬£¬£¬£¬¾ßÓÐÒ××°Öᢿçƽ̨¡¢ÇáÁ¿¼¶µÈÌØµã£¬£¬£¬£¬£¬£¬Ê¹ÓÃÕßÖÚ¶à¡£¡£¡£¡£¡£¡£Æä0.11.66¼°ÒÔǰ°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¨go-macaron/session¿â£©Ã»ÓжÔsessionid¾ÙÐÐУÑ飬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓöñÒâsessionid¼´¿É¶ÁÈ¡í§ÒâÎļþ£¬£¬£¬£¬£¬£¬Í¨¹ý¿ØÖÆÎļþÄÚÈÝÀ´¿ØÖÆsessionÄÚÈÝ£¬£¬£¬£¬£¬£¬½ø¶øµÇ¼í§ÒâÕË»§¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÉϰ¶í§ÒâÕ˺ŰüÀ¨ÖÎÀíÔ±Õ˺Å£¬£¬£¬£¬£¬£¬Í¬Ê±¿ÉʹÓÃgithooksÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬Í¬Ê±±£´æÑÏÖØµÄԽȨºÍÏÂÁîÖ´ÐÐÎÊÌâ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SaltStack_δÊÚȨ»á¼û[CVE-2021-25281][CNNVD-202102-1696]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SaltAPIwheel_asyncδÊÚȨ»á¼ûÎó²îÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬Í¨¹ýwheel_asyncŲÓÃmasterµÄwheel²å¼þ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉÃô¸ÐÎļþÏÂÔØ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

·¢Ã÷Ãô¸ÐÎļþÏÂÔØÐÐΪ£¬£¬£¬£¬£¬£¬ÈçÏÂÔØ±¸·ÝÎļþ£¬£¬£¬£¬£¬£¬³ÌÐòÔ´Â룬£¬£¬£¬£¬£¬SQLÎļþ£¬£¬£¬£¬£¬£¬ÉèÖÃÎļþµÈÕâÀàÐÐΪ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉ¿ÉÖ´ÐÐÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»ú±£´æÉÏ´«¿ÉÒÉwebshellµ½Ä¿µÄipÖ÷»úµÄÐÐΪ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Java_ShellcodeÍâµØÀú³Ì×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWindowsVirtualMachineÀàÖеÄenqueueÒªÁì¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐJavaÍâµØÀú³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄpayload£¬£¬£¬£¬£¬£¬Ê¹ÓöñÒâÀà¾ÙÐÐÀú³Ì×¢ÈëÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CouchDB_±ÊֱԽȨÎó²î[CVE-2017-12635][CNNVD-201711-487]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â£¬£¬£¬£¬£¬£¬×¨×¢ÓÚÒ×ÓÃÐԺͳÉΪ¡±Íêȫӵ±§webµÄÊý¾Ý¿â¡±¡£¡£¡£¡£¡£¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌ㬣¬£¬£¬£¬£¬JavaScript×÷ΪÅÌÎÊÓïÑÔ£¬£¬£¬£¬£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£¡£µ¼ÖÂÎó²îµÄÔµ¹ÊÔ­ÓÉÊÇErlangºÍJavaScript£¬£¬£¬£¬£¬£¬¶ÔJSONÆÊÎö·½·¨µÄ²î±ð£¬£¬£¬£¬£¬£¬¹ØÓÚÖØ¸´µÄ¼üErlang»á´æ´¢Á½¸öÖµ£¬£¬£¬£¬£¬£¬¶øJavaScriptÖ»´æ´¢µÚ¶þ¸öÖµ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Discuz!ML_V3.X_ÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Discuz!MLϵͳ¶ÔcookieÖÐÎüÊÕµÄlanguage²ÎÊýÄÚÈÝδ¹ýÂË£¬£¬£¬£¬£¬£¬µ¼ÖÂ×Ö·û´®Æ´½Ó£¬£¬£¬£¬£¬£¬´Ó¶øÖ´ÐÐphp´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_OpenSSL_·´µ¯shellÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐOpenSSL·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£¡£¡£¡£¡£·´µ¯ÅþÁ¬£¬£¬£¬£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀͶË£¬£¬£¬£¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£¡£¡£¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¡£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_CMS-Phpcms:V9.5.8_ºǫ́getshell

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCMS-Phpcms:V9.5.8ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬£¬£¬¸ÃÎó²îʹÓÃcontent.phpÎļþ½á¹¹¶ñÒâpayload£¬£¬£¬£¬£¬£¬´Ó¶øÔì³É´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Covenant_ÅþÁ¬C2ЧÀÍÆ÷_ÉÏ´«ÐÅÏ¢»òÏÂÁî½»»¥

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

CovenantÊÇÒ»¸ö.NET¿ª·¢µÄC2(commandandcontrol)¿ò¼Ü£¬£¬£¬£¬£¬£¬Ê¹ÓÃ.NETCoreµÄ¿ª·¢ÇéÐΣ¬£¬£¬£¬£¬£¬²»µ«Ö§³ÖLinux£¬£¬£¬£¬£¬£¬MacOSºÍWindows£¬£¬£¬£¬£¬£¬»¹Ö§³ÖdockerÈÝÆ÷¡£¡£¡£¡£¡£¡£CovenantÖ§³Ö¶¯Ì¬±àÒ룬£¬£¬£¬£¬£¬Äܹ»½«ÊäÈëµÄC#´úÂëÉÏ´«ÖÁC2Server£¬£¬£¬£¬£¬£¬»ñµÃ±àÒëºóµÄÎļþ²¢Ê¹ÓÃAssembly.Load()´ÓÄÚ´æ¾ÙÐмÓÔØ¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÅú×¢£¬£¬£¬£¬£¬£¬CovenantµÄÌìÉúÎïGruntsľÂíºóÃÅÕýÔÚÅþÁ¬C2ЧÀÍÆ÷¾ÙÐÐÉÏ´«ÐÅÏ¢»òÏÂÁî½»»¥¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Alibaba-Canal-configÔÆÃÜÔ¿ÐÅϢй¶Îó²î

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

canalÊǰ¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌ⣬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄµØµã»á¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_laravel_pop3ʹÓÃÁ´¹¥»÷[CVE-2022-31279][CNNVD-202206-671]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Laravel9.1.8ÔÚ´¦Öóͷ£¹¥»÷Õß¿ØÖƵķ´ÐòÁл¯Êý¾Ýʱ£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýIlluminate\Broadcasting\PendingBroadcast.phpÖеÄ__destructºÍFaker\Generator.phpÖеÄ__callÖеÄδÐòÁл¯µ¯³öÁ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖУ¬£¬£¬£¬£¬£¬Ò»Ð©Ê¾ÀýDAGûÓÐ׼ȷÕûÀíÓû§ÌṩµÄ²ÎÊý£¬£¬£¬£¬£¬£¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSÏÂÁî×¢ÈëµÄÓ°Ïì¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.7.1ÒÔÏÂ_·ÇÊÚȨ»á¼û[CVE-2020-17523][CNNVD-202102-238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬ÊÚȨµÈ¡£¡£¡£¡£¡£¡£¹ØÓÚApacheShiro1.7.1֮ǰµÄ°æ±¾£¬£¬£¬£¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SangforEDR²»¸ßÓÚ3.2.19_·ÇÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÊÔͼͨ¹ýSangforEDRµÄ·ÇÊÚȨ»á¼ûÎó²î£¬£¬£¬£¬£¬£¬ÊäÈëuser=admin¼´¿É»ñÈ¡Óû§È¨ÏÞ¡£¡£¡£¡£¡£¡£SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÐÅ·þ¹«Ë¾ÌṩµÄÒ»Ì×ÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CLTPHP-v5.8_ºǫ́í§ÒâÎļþɾ³ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

CLTPHPÊÇ»ùÓÚThinkPHP5¿ª·¢£¬£¬£¬£¬£¬£¬ºǫ́½ÓÄÉLayui¿ò¼ÜµÄÄÚÈÝÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£CLTPHP5.8¼°Ö®Ç°°æ±¾±£´æºǫ́í§ÒâÎļþɾ³ýÎó²î£¬£¬£¬£¬£¬£¬Í¨¹ý½á¹¹¶ñÒâpayload¹¥»÷Õß¿Éɾ³ýϵͳÖеÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_AspectJWeaver_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃaspectjweaverµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁ˱£´æaspectjweaver:1.9.2,commons-collections:3.2.2µÄÒÀÀµ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Gila-CMS-2.0.0_ÎļþдÈë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

GilaCMS2.0.0°æ±¾¼°ÒÔϰ汾»á½«User-AgentÖеÄÄÚÈÝдÈëµ½GSESSIONIDcookieÖÐÖ¸¶¨µÄÎļþÖУ¬£¬£¬£¬£¬£¬Òò´Ë¿ÉÒÔʹÓÃÕâµã½«webshellдÈëµ½phpÎļþÖУ¬£¬£¬£¬£¬£¬Ôì³Éí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_service.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚservice.phpÖжԴ«ÈëµÄservice_path²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_PrivManager.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚPrivManager.phpÖжԴ«ÈëµÄmode_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_SetVer.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚSetVer.phpÖжԴ«ÈëµÄversion_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_PHP-8.1.0-dev_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

PHP8.1.0-devÓÚ2021Äê3ÔÂ28ÈÕÐû²¼µÄ°æ±¾Öб£´æºóÃÅ£¬£¬£¬£¬£¬£¬Í¨¹ýUser-AgenttÍ·¿ÉÒÔÖ´ÐÐí§Òâ´úÂë»òÏÂÁî

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring3_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSpring3µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËspring-tx:5.2.3.RELEASE,spring-context:5.2.3.RELEASE,javax.transaction-api:1.2£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JRMPListener_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJRMPListenerµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Ææ°²ÐÅÖÕ¶ËÇå¾²ÖÎÀíϵͳÌìÇæÔ½È¨»á¼ûÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓÃÌìÇæÇ°Ì¨Ö±½Ó»á¼ûĿ¼¿É»ñÈ¡Êý¾Ý¿âÏà¹ØÐÅÏ¢

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear-½»Á÷»ú_ÏÂÁî×¢Èë[CVE-2021-33514][CNNVD-202105-1401]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

×°±¸ÔÚÎüÊÕµ½setup.cgi?token=';$HTTP_USER_AGENT;'Ò»ÀàÊý¾ÝÊ£¬£¬£¬£¬£¬£¬ÓÉÓÚδ¾ÙÐÐÇå¾²¹ýÂË£¬£¬£¬£¬£¬£¬±£´æ±»¹¥»÷Õßͨ¹ý¾ÓÐĽṹµÄ¶ñÒâÊý¾Ý¹¥»÷£¬£¬£¬£¬£¬£¬µ¼ÖÂÔÚ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Ãô¸ÐÐÅϢй¶_³£¼ûÃô¸ÐÎļþ»á¼û

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÄ¿µÄipÖ÷»úÖпÉÄÜ̻¶ÔÚÍâµÄÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Oracle_WebLogic_·´ÐòÁл¯Îó²î[CVE-2019-2725/CVE-2019-2729]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

´ËÎó²îÊÇÓÉÓÚÓ¦ÓÃÔÚ´¦Öóͷ£·´ÐòÁл¯ÊäÈëÐÅϢʱ±£´æÈ±ÏÝ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÈ«ÐĽṹµÄ¶ñÒâHTTPÇëÇ󣬣¬£¬£¬£¬£¬ÓÃÓÚ»ñµÃÄ¿µÄЧÀÍÆ÷µÄȨÏÞ£¬£¬£¬£¬£¬£¬²¢ÔÚδÊÚȨµÄÇéÐÎÏÂÖ´ÐÐÔ¶³ÌÏÂÁ£¬£¬£¬£¬£¬×îÖÕ»ñȡЧÀÍÆ÷µÄȨÏÞ¡£¡£¡£¡£¡£¡£CVE-2019-2729ÊÇCVE-2019-2725µÄÈÆ¹ý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_DolphinScheduler_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-11974][CNNVD-202012-1358]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApacheDolphinSchedulerµÄJDBC¿Í»§¶Ë¾ÙÐз´ÐòÁл¯²Ù×÷½ø¶øµ¼ÖÂÔ¶³Ì´úÖ´ÐС£¡£¡£¡£¡£¡£ApacheDolphinScheduler(Incubator,Ô­EasyScheduler)ÊÇÒ»¸öÂþÑÜʽÊý¾ÝÊÂÇéÁ÷ʹÃüµ÷Àíϵͳ£¬£¬£¬£¬£¬£¬Ö÷Òª½â¾öÊý¾ÝÑз¢ETL´í×ÛÖØ´óµÄÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬£¬¶ø²»¿ÉÖ±¹Û¼à¿ØÊ¹Ãü¿µ½¡×´Ì¬µÈÎÊÌâ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Horde_Groupware_Webmail_Edition_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î[ZDI-20-1051]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

HordeGroupwareWebmailÊÇÃÀ¹úHorde¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷µÄÆóÒµ¼¶Í¨Ñ¶Ì×¼þ¡£¡£¡£¡£¡£¡£HordeGroupwareWebmailÖб£´æ´úÂë×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷ÕßÔÚIMP_Prefs_SortÀàµÄ½á¹¹º¯ÊýÖжԲ»ÊÜÐÅÈεÄÊý¾ÝÎó²î¾ÙÐз´ÐòÁл¯¡£¡£¡£¡£¡£¡£µÍÌØÈ¨µÄ¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µãÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MidaSolutionseFramework_ajaxreq.phpÏÂÁî×¢ÈëÎó²î[CVE-2020-15920][CNNVD-202007-1517]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

MidaSolutionsÊÇÒ»¼ÒרעÓÚͳһͨѶ(UC)µÄ¸ßÊÖÒÕÒâ´óÀû¹«Ë¾,MidaÍŶÓÒѳÉΪͳһЭ×÷ºÍרҵÏàͬµÄÈ«ÇòÏòµ¼Õß,ÏÕЩËùÓÐÐÐÒµµÄЧÀÍÌṩÉÌ£¬£¬£¬£¬£¬£¬ÏµÍ³¼¯³ÉÉÌ¡£¡£¡£¡£¡£¡£ÆäÏàÖúͬ°éÓÐ΢Èí,˼¿Æ,»ÝÆÕ,ÖйúµçÐŵÈ40¸öÌìÏÂ×ÅÃûÆóÒµ¡£¡£¡£¡£¡£¡£MidaeFrameworkÊÇMidaSolutions¹«Ë¾ÆìÏÂÊÓÆµºÍÓïÒôÓ¦ÓóÌÐòµÄÍêÕûЧÀÍÌ×¼þ£¬£¬£¬£¬£¬£¬ÓëÏÕЩËùÓÐÖ÷ÒªµÄUCƽ̨¼æÈÝ¡£¡£¡£¡£¡£¡£¸ÃÌ×¼þ°üÀ¨»°ÎñÔ±¿ØÖÆÌ¨£¬£¬£¬£¬£¬£¬¼Í¼Æ÷£¬£¬£¬£¬£¬£¬´«ÕæÐ§ÀÍÆ÷£¬£¬£¬£¬£¬£¬¼Æ·Ñ£¬£¬£¬£¬£¬£¬ÐÐÁÐÖÎÀíÆ÷£¬£¬£¬£¬£¬£¬×Ô¶¯»°ÎñÔ±£¬£¬£¬£¬£¬£¬Òƶ¯Ó¦ÓóÌÐò£¬£¬£¬£¬£¬£¬µç»°Ð§ÀÍ¡£¡£¡£¡£¡£¡£MidaSolutionseFramework2.9.0¼°Ö®Ç°°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£Ëüʹδ¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷ÕßÄܹ»»ñµÃ¾ßÓÐÖÎÀí£¨root£©ÌØÈ¨µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¡£¡£×¢ÈëµãλÓÚδ¹ûÕæµÄPHPÒ³ÃæÉÏ£¬£¬£¬£¬£¬£¬¸ÃÒ³Ãæ¿ÉÒÔʹÓÃGET»òPOST¶ñÒâ¸ºÔØ×÷ΪĿµÄ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_SaltStack_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-16846/CVE-2020-25592][CNNVD-202011-302/CNNVD-202011-308]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÕýÔÚʹÓÃSaltStackµÄsalt-api½Ó¿ÚÖ´ÐÐí§ÒâÏÂÁî £»£»£»£»£»SaltStackÊÇÒ»¸öÂþÑÜʽÔËάϵͳ£¬£¬£¬£¬£¬£¬ÔÚ»¥ÁªÍø³¡¾°Öб»ÆÕ±éÓ¦Ó㬣¬£¬£¬£¬£¬ÓÐÒÔÏÂÁ½¸öÖ÷Òª¹¦Ð§£ºÉèÖÃÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬Äܹ»½«Ô¶³Ì½Úµãά»¤ÔÚÒ»¸öÔ¤½ç˵µÄ״̬£¨ÀýÈ磬£¬£¬£¬£¬£¬È·±£×°ÖÃÌØ¶¨µÄÈí¼þ°ü²¢ÔËÐÐÌØ¶¨µÄЧÀÍ£©ÂþÑÜʽԶ³ÌÖ´ÐÐϵͳ£¬£¬£¬£¬£¬£¬ÓÃÓÚÔÚÔ¶³Ì½ÚµãÉϵ¥¶À»òͨ¹ýí§ÒâÑ¡Ôñ±ê×¼À´Ö´ÐÐÏÂÁîºÍÅÌÎÊÊý¾Ý¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÓÉÁ½¸ö×éºÏµÄCVEÎó²îµÄʹÓñ¬·¢£¬£¬£¬£¬£¬£¬Í¨¹ýCVE-2020-25592½á¹¹í§Òâ¡°eauth¡±/¡°token¡±Öµ£¬£¬£¬£¬£¬£¬ÈƹýÉí·ÝÈÏÖ¤ £»£»£»£»£»Í¨¹ýCVE-2020-16846Ö´ÐÐshell¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_SQL_Server_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0618][CNNVD-202002-496]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS)£¬£¬£¬£¬£¬£¬ÊÇÏÖÔÚÌìÏÂÉÏÆÕ±éʹÓõÄÊý¾Ý¿âÖ®Ò»¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹÓôËÎó²îÔÚ±¨±íЧÀÍÆ÷ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_PHP·´ÐòÁл¯¹¤Ç©×ÖÌÃÊý¾Ý·¢Ã÷

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

Èô³ÌÐòδ¶ÔÓû§ÊäÈëµÄÐòÁл¯×Ö·û´®¾ÙÐмì²â£¬£¬£¬£¬£¬£¬Ôò¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔ¿ØÖÆ·´ÐòÁл¯Àú³Ì£¬£¬£¬£¬£¬£¬Í¨¹ýÔÚ²ÎÊýÖÐ×¢ÈëһЩ´úÂ룬£¬£¬£¬£¬£¬´Ó¶øµÖ´ï´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬SQL×¢È룬£¬£¬£¬£¬£¬Ä¿Â¼±éÀúµÈ²»¿É¿ØÐ§¹û¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220708