ÿÖÜÉý¼¶Í¨¸æ-2022-11-01

Ðû²¼Ê±¼ä 2022-11-01
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_drag-and-drop-multiple-file-uploader_ÎļþÉÏ´«[CVE-2020-12800][CNNVD-202006-519]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWordPressdraganddropmultiplefileuploader²å¼þ1.3.3.3֮ǰ°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î £¬£¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ ¡£¡£¡£¡£¡£DragandDropMultipleFileUploaderÊÇContactForm7µÄÒ»¸ö¼òÆÓ¡¢Ö±½ÓµÄWordPress²å¼þÀ©Õ¹ £¬£¬£¬£¬£¬ËüÔÊÐíÓû§Ê¹ÓÃÍϷŹ¦Ð§»òWeb±íµ¥µÄͨÓÃä¯ÀÀÎļþÉÏ´«¶à¸öÎļþ ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_vTiger_CRM_ÎļþÉÏ´«[CVE-2013-3591][CNNVD-201310-746]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃvTigerCRM5.3.0ÒÔ¼°5.4.0°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î £¬£¬£¬£¬£¬´Ó¶øÔÚÉϰ¶ºó»ñȡĿµÄϵͳµÄȨÏÞ ¡£¡£¡£¡£¡£VtigerCRMÊÇÃÀ¹úVtiger¹«Ë¾µÄÒ»Ì×»ùÓÚSugarCRM¿ª·¢µÄ¿Í»§¹ØÏµÖÎÀíϵͳ£¨CRM£© £¬£¬£¬£¬£¬ËüÌṩÖÎÀí¡¢ÍøÂç¡¢ÆÊÎö¿Í»§ÐÅÏ¢µÈ¹¦Ð§

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Sophos_Firewall_´úÂëÖ´ÐÐ[CVE-2022-3236]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSophosFirewallv19.0MR1(19.0.1)ÒÔ¼°Ö®Ç°°æ±¾Öб£´æµÄ´úÂëÖ´ÐÐÎó²î £¬£¬£¬£¬£¬´Ó¶øÄ¿µÄϵͳȨÏÞ ¡£¡£¡£¡£¡£SophosXGFirewallÊÇSophos¹«Ë¾Äܹ»Íêȫʶ±ðÍøÂçÉϱ»Ñ¬È¾µÄÓû§ £¬£¬£¬£¬£¬²¢×Ô¶¯ÏÞÖÆ¶ÔÆäËûÍøÂç×ÊÔ´µÄ»á¼ûµÄÍøÂçÇå¾²½â¾ö¼Æ»® ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢_E-office10ǰ̨_í§ÒâÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚͨ¹ý·ºÎ¢_E-office10ǰ̨µÄOfficeServer.phpÒ³ÃæÉÏ´«í§ÒâÎļþ£»£»£»£»£»Í¨¹ý´ËÎó²î¹¥»÷Õß¿ÉÉÏ´«í§ÒâÃûÌõÄÎļþ £¬£¬£¬£¬£¬ºó¶ËЧÀÍÆ÷»áÀֳɯÊÎö¸ÃÎļþ £¬£¬£¬£¬£¬µ¼Ö¿Éͨ¹ý´ËÎó²îÖ±½Ó»ñȡϵͳȨÏÞ ¡£¡£¡£¡£¡£·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú ¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖÐ £¬£¬£¬£¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢Èë £¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü £¬£¬£¬£¬£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌà £¬£¬£¬£¬£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯ ¡£¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦ £¬£¬£¬£¬£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑé £¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü £¬£¬£¬£¬£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101