ÿÖÜÉý¼¶Í¨¸æ-2022-07-08

Ðû²¼Ê±¼ä 2022-07-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Confluence_í§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2019-3396][CNNVD-201903-909]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ConfluenceÊÇ¿îÆóҵ֪ʶ¿âÈí¼þ¡£¡£ÆäÖÐConfluenceServerºÍDataCenter²úÆ·ÖÐʹÓõÄС¹¤¾ßÅþÁ¬Æ÷widgetconnecter×é¼þ£¨°æ±¾<=3.1.3£©Öб£´æí§ÒâÎļþ¶ÁÈ¡Îó²î

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_UCM6202_1.0.18.13Ô¶³ÌÏÂÁî×¢ÈëÎó²î[CVE-2020-5722][CNNVD-202003-1337]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

GrandstreamUCM6200ϵÁеÄHTTP½Ó¿ÚÈÝÒ×Êܵ½È«ÐÄÉè¼ÆµÄHTTPÇëÇóδ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌSQL×¢ÈëµÄ¹¥»÷¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÒÔrootÉí·ÝÔÚ1.0.19.20֮ǰµÄ°æ±¾ÖÐÖ´ÐÐshellÏÂÁî £¬£¬£¬£¬»òÔÚ1.0.20.17֮ǰµÄ°æ±¾ÖеÄÃÜÂë»Ö¸´µç×ÓÓʼþÖÐ×¢ÈëHTML¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear_R7000_RouterÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

NetgearR7000,¹Ì¼þ°æ±¾1.0.7.2_1.1.93ÒÔ¼°¸üÔçÆÚ°æ±¾ £¬£¬£¬£¬R6400¹Ì¼þ°æ±¾1.0.1.6_1.0.4ÒÔ¼°¸üÔçÆÚ°æ±¾,°üÀ¨Ò»¸ö°üÀ¨í§ÒâÏÂÁî×¢ÈëÎó²î.¹¥»÷Õß¿ÉÄÜÓÕʹÓû§»á¼ûÇÉÈ«ÐÄ˼¹¹½¨µÄwebÕ¾µã £¬£¬£¬£¬´Ó¶øÒÔ¸ùÓû§È¨ÏÞÔÚÊÜÓ°ÏìµÄ·ÓÉÆ÷ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_shadowÄÚÈÝÎļþ»ØÏÔ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

·¢Ã÷ÓÐetc/shadowÎļþµÄ»ØÏÔÒ³Ãæ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕß £¬£¬£¬£¬ÔËÐÐºó £¬£¬£¬£¬¿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾ £¬£¬£¬£¬ÈçºóÃŵÈ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ʵÑéÅþÁ¬¿ó³Ø(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÍÚ¿óľÂíÊÔͼÅþÁ¬Ô¶³Ì¿ó³ØÐ§ÀÍÆ÷¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò £¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò £¬£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ· £¬£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ· £¬£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ÅþÁ¬¿ó³ØÀÖ³É(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÍÚ¿óľÂíÅþÁ¬Ô¶³Ì¿ó³ØÐ§ÀÍÆ÷ÀֳɵÄÐÐΪ¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò £¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò £¬£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ· £¬£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ· £¬£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_»ñÈ¡ÍÚ¿óʹÃü(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½´Ó¿ó³ØÏò¿ó»úÏ·¢ÍÚ¿óʹÃüµÄÐÐΪ¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò £¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò £¬£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ· £¬£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ· £¬£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_CPUMiner_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_¿ó»úÉèÖù²ÏíÄ¿µÄ(BTC/LTC)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½¿ó»úÏò¿ó³ØÅú×¢¶Ô¹²ÏíÄ¿µÄµÄÆ«ºÃµÄÐÐΪ¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCPUMinerÍÚ¿óľÂí¡£¡£CPUMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò £¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_H2database_console_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪÍⲿ¶ñÒâjndiЧÀÍÆ÷µØµã¡£¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ £¬£¬£¬£¬½ÓÄÉjavaÓïÑÔ±àд £¬£¬£¬£¬²»ÊÜÆ½Ì¨µÄÏÞÖÆ £¬£¬£¬£¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸öÊ®·ÖÀû±ãµÄweb¿ØÖÆÌ¨ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£¡£H2Database»¹Ìṩ¼æÈÝģʽ £¬£¬£¬£¬¿ÉÒÔ¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â £¬£¬£¬£¬Òò´Ë½ÓÄÉH2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿âºÜÊÇÀû±ã¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CMS_Joomla´úÂëÖ´ÐÐ[CVE-2020-10238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Joomla!ÊÇÃÀ¹úOpenSourceMattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£JoomlaÊÇÒ»Ì×ÄÚÈÝÖÎÀíϵͳ £¬£¬£¬£¬ÊÇʹÓÃPHPÓïÑÔ¼ÓÉÏMYSQLÊý¾Ý¿âËù¿ª·¢µÄÈí¼þϵͳ¡£¡£ÓÉÓÚjoomlaȨÏÞ·ÖÅɲ»¶ÔÀíµ¼ÖÂÖÎÀíԱȨÏÞÕ˺ſɶÔÏà¹ØphpÒ³Ãæ¾ÙÐб༭ £¬£¬£¬£¬²åÈëÏà¹Ø¶ñÒâ´úÂëµ¼ÖÂÏÂÁîÖ´ÐС£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_HTTP_Server_·¾¶´©Ô½Îó²î[CVE-2021-42013][CNNVD-202110-413]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»úͨ¹ýApacheHTTPServer¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£Apache_HTTP_ServerÊÇApache»ù´¡¿ª·ÅµÄÊ¢ÐеÄHTTPЧÀÍÆ÷¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Gogs_session_δÊÚȨ»á¼û[CVE-2018-18925][CNNVD-201811-049]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

gogsÊÇÒ»¿î¼«Ò״µÄ×ÔÖúGitЧÀÍÆ½Ì¨ £¬£¬£¬£¬¾ßÓÐÒ××°Öᢿçƽ̨¡¢ÇáÁ¿¼¶µÈÌØµã £¬£¬£¬£¬Ê¹ÓÃÕßÖÚ¶à¡£¡£Æä0.11.66¼°ÒÔǰ°æ±¾ÖÐ £¬£¬£¬£¬£¨go-macaron/session¿â£©Ã»ÓжÔsessionid¾ÙÐÐУÑé £¬£¬£¬£¬¹¥»÷ÕßʹÓöñÒâsessionid¼´¿É¶ÁÈ¡í§ÒâÎļþ £¬£¬£¬£¬Í¨¹ý¿ØÖÆÎļþÄÚÈÝÀ´¿ØÖÆsessionÄÚÈÝ £¬£¬£¬£¬½ø¶øµÇ¼í§ÒâÕË»§¡£¡£¹¥»÷Õß¿ÉÉϰ¶í§ÒâÕ˺ŰüÀ¨ÖÎÀíÔ±Õ˺Š£¬£¬£¬£¬Í¬Ê±¿ÉʹÓÃgithooksÖ´ÐÐí§ÒâÏÂÁî £¬£¬£¬£¬Í¬Ê±±£´æÑÏÖØµÄԽȨºÍÏÂÁîÖ´ÐÐÎÊÌâ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SaltStack_δÊÚȨ»á¼û[CVE-2021-25281][CNNVD-202102-1696]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SaltAPIwheel_asyncδÊÚȨ»á¼ûÎó²îÖÐ £¬£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇó £¬£¬£¬£¬Í¨¹ýwheel_asyncŲÓÃmasterµÄwheel²å¼þ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉÃô¸ÐÎļþÏÂÔØ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

·¢Ã÷Ãô¸ÐÎļþÏÂÔØÐÐΪ £¬£¬£¬£¬ÈçÏÂÔØ±¸·ÝÎļþ £¬£¬£¬£¬³ÌÐòÔ´Âë £¬£¬£¬£¬SQLÎļþ £¬£¬£¬£¬ÉèÖÃÎļþµÈÕâÀàÐÐΪ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉ¿ÉÖ´ÐÐÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»ú±£´æÉÏ´«¿ÉÒÉwebshellµ½Ä¿µÄipÖ÷»úµÄÐÐΪ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Java_ShellcodeÍâµØÀú³Ì×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWindowsVirtualMachineÀàÖеÄenqueueÒªÁì¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐJavaÍâµØÀú³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄpayload £¬£¬£¬£¬Ê¹ÓöñÒâÀà¾ÙÐÐÀú³Ì×¢ÈëÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂë £¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CouchDB_±ÊֱԽȨÎó²î[CVE-2017-12635][CNNVD-201711-487]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â £¬£¬£¬£¬×¨×¢ÓÚÒ×ÓÃÐԺͳÉΪ¡±Íêȫӵ±§webµÄÊý¾Ý¿â¡±¡£¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌà £¬£¬£¬£¬JavaScript×÷ΪÅÌÎÊÓïÑÔ £¬£¬£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£¡£µ¼ÖÂÎó²îµÄÔµ¹ÊÔ­ÓÉÊÇErlangºÍJavaScript £¬£¬£¬£¬¶ÔJSONÆÊÎö·½·¨µÄ²î±ð £¬£¬£¬£¬¹ØÓÚÖØ¸´µÄ¼üErlang»á´æ´¢Á½¸öÖµ £¬£¬£¬£¬¶øJavaScriptÖ»´æ´¢µÚ¶þ¸öÖµ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Discuz!ML_V3.X_ÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Discuz!MLϵͳ¶ÔcookieÖÐÎüÊÕµÄlanguage²ÎÊýÄÚÈÝδ¹ýÂË £¬£¬£¬£¬µ¼ÖÂ×Ö·û´®Æ´½Ó £¬£¬£¬£¬´Ó¶øÖ´ÐÐphp´úÂë¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_OpenSSL_·´µ¯shellÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐOpenSSL·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£·´µ¯ÅþÁ¬ £¬£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀÍ¶Ë £¬£¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_CMS-Phpcms:V9.5.8_ºǫ́getshell

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCMS-Phpcms:V9.5.8ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ £¬£¬£¬£¬¸ÃÎó²îʹÓÃcontent.phpÎļþ½á¹¹¶ñÒâpayload £¬£¬£¬£¬´Ó¶øÔì³É´úÂëÖ´ÐС£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Covenant_ÅþÁ¬C2ЧÀÍÆ÷_ÉÏ´«ÐÅÏ¢»òÏÂÁî½»»¥

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

CovenantÊÇÒ»¸ö.NET¿ª·¢µÄC2(commandandcontrol)¿ò¼Ü £¬£¬£¬£¬Ê¹ÓÃ.NETCoreµÄ¿ª·¢ÇéÐÎ £¬£¬£¬£¬²»µ«Ö§³ÖLinux £¬£¬£¬£¬MacOSºÍWindows £¬£¬£¬£¬»¹Ö§³ÖdockerÈÝÆ÷¡£¡£CovenantÖ§³Ö¶¯Ì¬±àÒë £¬£¬£¬£¬Äܹ»½«ÊäÈëµÄC#´úÂëÉÏ´«ÖÁC2Server £¬£¬£¬£¬»ñµÃ±àÒëºóµÄÎļþ²¢Ê¹ÓÃAssembly.Load()´ÓÄÚ´æ¾ÙÐмÓÔØ¡£¡£¸ÃÊÂÎñÅú×¢ £¬£¬£¬£¬CovenantµÄÌìÉúÎïGruntsľÂíºóÃÅÕýÔÚÅþÁ¬C2ЧÀÍÆ÷¾ÙÐÐÉÏ´«ÐÅÏ¢»òÏÂÁî½»»¥¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Alibaba-Canal-configÔÆÃÜÔ¿ÐÅϢй¶Îó²î

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

canalÊǰ¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌâ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄµØµã»á¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_laravel_pop3ʹÓÃÁ´¹¥»÷[CVE-2022-31279][CNNVD-202206-671]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Laravel9.1.8ÔÚ´¦Öóͷ£¹¥»÷Õß¿ØÖƵķ´ÐòÁл¯Êý¾Ýʱ £¬£¬£¬£¬ÔÊÐíͨ¹ýIlluminate\Broadcasting\PendingBroadcast.phpÖеÄ__destructºÍFaker\Generator.phpÖеÄ__callÖеÄδÐòÁл¯µ¯³öÁ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖÐ £¬£¬£¬£¬Ò»Ð©Ê¾ÀýDAGûÓÐ׼ȷÕûÀíÓû§ÌṩµÄ²ÎÊý £¬£¬£¬£¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSÏÂÁî×¢ÈëµÄÓ°Ïì¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.7.1ÒÔÏÂ_·ÇÊÚȨ»á¼û[CVE-2020-17523][CNNVD-202102-238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü £¬£¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤ £¬£¬£¬£¬ÊÚȨµÈ¡£¡£¹ØÓÚApacheShiro1.7.1֮ǰµÄ°æ±¾ £¬£¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ £¬£¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SangforEDR²»¸ßÓÚ3.2.19_·ÇÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÊÔͼͨ¹ýSangforEDRµÄ·ÇÊÚȨ»á¼ûÎó²î £¬£¬£¬£¬ÊäÈëuser=admin¼´¿É»ñÈ¡Óû§È¨ÏÞ¡£¡£SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÐÅ·þ¹«Ë¾ÌṩµÄÒ»Ì×ÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CLTPHP-v5.8_ºǫ́í§ÒâÎļþɾ³ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

CLTPHPÊÇ»ùÓÚThinkPHP5¿ª·¢ £¬£¬£¬£¬ºǫ́½ÓÄÉLayui¿ò¼ÜµÄÄÚÈÝÖÎÀíϵͳ¡£¡£CLTPHP5.8¼°Ö®Ç°°æ±¾±£´æºǫ́í§ÒâÎļþɾ³ýÎó²î £¬£¬£¬£¬Í¨¹ý½á¹¹¶ñÒâpayload¹¥»÷Õß¿Éɾ³ýϵͳÖеÄí§ÒâÎļþ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_AspectJWeaver_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃaspectjweaverµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁ˱£´æaspectjweaver:1.9.2,commons-collections:3.2.2µÄÒÀÀµ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß £¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂë £¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Gila-CMS-2.0.0_ÎļþдÈë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

GilaCMS2.0.0°æ±¾¼°ÒÔϰ汾»á½«User-AgentÖеÄÄÚÈÝдÈëµ½GSESSIONIDcookieÖÐÖ¸¶¨µÄÎļþÖÐ £¬£¬£¬£¬Òò´Ë¿ÉÒÔʹÓÃÕâµã½«webshellдÈëµ½phpÎļþÖÐ £¬£¬£¬£¬Ôì³Éí§Òâ´úÂëÖ´ÐС£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_service.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î £¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚservice.phpÖжԴ«ÈëµÄservice_path²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇó £¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_PrivManager.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î £¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚPrivManager.phpÖжԴ«ÈëµÄmode_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇó £¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_SetVer.php_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉϺ£¸ñ¶ûÇå¾²ÈÏÖ¤Íø¹ØÖÎÀíϵͳ±£´æÒ»¸öÏÂÁîÖ´ÐÐÎó²î £¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚSetVer.phpÖжԴ«ÈëµÄversion_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÇëÇó £¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_PHP-8.1.0-dev_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

PHP8.1.0-devÓÚ2021Äê3ÔÂ28ÈÕÐû²¼µÄ°æ±¾Öб£´æºóÃÅ £¬£¬£¬£¬Í¨¹ýUser-AgenttÍ·¿ÉÒÔÖ´ÐÐí§Òâ´úÂë»òÏÂÁî

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring3_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSpring3µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËspring-tx:5.2.3.RELEASE,spring-context:5.2.3.RELEASE,javax.transaction-api:1.2 £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß £¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî £¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JRMPListener_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJRMPListenerµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß £¬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂë £¬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Ææ°²ÐÅÖÕ¶ËÇå¾²ÖÎÀíϵͳÌìÇæÔ½È¨»á¼ûÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓÃÌìÇæÇ°Ì¨Ö±½Ó»á¼ûĿ¼¿É»ñÈ¡Êý¾Ý¿âÏà¹ØÐÅÏ¢

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear-½»Á÷»ú_ÏÂÁî×¢Èë[CVE-2021-33514][CNNVD-202105-1401]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

×°±¸ÔÚÎüÊÕµ½setup.cgi?token=';$HTTP_USER_AGENT;'Ò»ÀàÊý¾ÝÊ £¬£¬£¬£¬ÓÉÓÚδ¾ÙÐÐÇå¾²¹ýÂË £¬£¬£¬£¬±£´æ±»¹¥»÷Õßͨ¹ý¾ÓÐĽṹµÄ¶ñÒâÊý¾Ý¹¥»÷ £¬£¬£¬£¬µ¼ÖÂÔÚ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Ãô¸ÐÐÅϢй¶_³£¼ûÃô¸ÐÎļþ»á¼û

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÄ¿µÄipÖ÷»úÖпÉÄÜ̻¶ÔÚÍâµÄÃô¸ÐÎļþ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Oracle_WebLogic_·´ÐòÁл¯Îó²î[CVE-2019-2725/CVE-2019-2729]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

´ËÎó²îÊÇÓÉÓÚÓ¦ÓÃÔÚ´¦Öóͷ£·´ÐòÁл¯ÊäÈëÐÅϢʱ±£´æÈ±ÏÝ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÈ«ÐĽṹµÄ¶ñÒâHTTPÇëÇó £¬£¬£¬£¬ÓÃÓÚ»ñµÃÄ¿µÄЧÀÍÆ÷µÄȨÏÞ £¬£¬£¬£¬²¢ÔÚδÊÚȨµÄÇéÐÎÏÂÖ´ÐÐÔ¶³ÌÏÂÁî £¬£¬£¬£¬×îÖÕ»ñȡЧÀÍÆ÷µÄȨÏÞ¡£¡£CVE-2019-2729ÊÇCVE-2019-2725µÄÈÆ¹ý¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_DolphinScheduler_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-11974][CNNVD-202012-1358]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApacheDolphinSchedulerµÄJDBC¿Í»§¶Ë¾ÙÐз´ÐòÁл¯²Ù×÷½ø¶øµ¼ÖÂÔ¶³Ì´úÖ´ÐС£¡£ApacheDolphinScheduler(Incubator,Ô­EasyScheduler)ÊÇÒ»¸öÂþÑÜʽÊý¾ÝÊÂÇéÁ÷ʹÃüµ÷Àíϵͳ £¬£¬£¬£¬Ö÷Òª½â¾öÊý¾ÝÑз¢ETL´í×ÛÖØ´óµÄÒÀÀµ¹ØÏµ £¬£¬£¬£¬¶ø²»¿ÉÖ±¹Û¼à¿ØÊ¹Ãü¿µ½¡×´Ì¬µÈÎÊÌâ¡£¡£

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Horde_Groupware_Webmail_Edition_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î[ZDI-20-1051]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

HordeGroupwareWebmailÊÇÃÀ¹úHorde¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷µÄÆóÒµ¼¶Í¨Ñ¶Ì×¼þ¡£¡£HordeGroupwareWebmailÖб£´æ´úÂë×¢ÈëÎó²î¡£¡£ÔÊÐí¹¥»÷ÕßÔÚIMP_Prefs_SortÀàµÄ½á¹¹º¯ÊýÖжԲ»ÊÜÐÅÈεÄÊý¾ÝÎó²î¾ÙÐз´ÐòÁл¯¡£¡£µÍÌØÈ¨µÄ¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µãÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

¸üÐÂʱ¼ä£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MidaSolutionseFramework_ajaxreq.phpÏÂÁî×¢ÈëÎó²î[CVE-2020-15920][CNNVD-202007-1517]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

MidaSolutionsÊÇÒ»¼ÒרעÓÚͳһͨѶ(UC)µÄ¸ßÊÖÒÕÒâ´óÀû¹«Ë¾,MidaÍŶÓÒѳÉΪͳһЭ×÷ºÍרҵÏàͬµÄÈ«ÇòÏòµ¼Õß,ÏÕЩËùÓÐÐÐÒµµÄЧÀÍÌṩÉÌ £¬£¬£¬£¬ÏµÍ³¼¯³ÉÉÌ¡£¡£ÆäÏàÖúͬ°éÓÐ΢Èí,˼¿Æ,»ÝÆÕ,ÖйúµçÐŵÈ40¸öÌìÏÂ×ÅÃûÆóÒµ¡£¡£MidaeFrameworkÊÇMidaSolutions¹«Ë¾ÆìÏÂÊÓÆµºÍÓïÒôÓ¦ÓóÌÐòµÄÍêÕûЧÀÍÌ×¼þ £¬£¬£¬£¬ÓëÏÕЩËùÓÐÖ÷ÒªµÄUCƽ̨¼æÈÝ¡£¡£¸ÃÌ×¼þ°üÀ¨»°ÎñÔ±¿ØÖÆÌ¨ £¬£¬£¬£¬¼Í¼Æ÷ £¬£¬£¬£¬´«ÕæÐ§ÀÍÆ÷ £¬£¬£¬£¬¼Æ·Ñ £¬£¬£¬£¬ÐÐÁÐÖÎÀíÆ÷ £¬£¬£¬£¬×Ô¶¯»°ÎñÔ± £¬£¬£¬£¬Òƶ¯Ó¦ÓóÌÐò £¬£¬£¬£¬µç»°Ð§ÀÍ¡£¡£MidaSolutionseFramework2.9.0¼°Ö®Ç°°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£Ëüʹδ¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷ÕßÄܹ»»ñµÃ¾ßÓÐÖÎÀí£¨root£©ÌØÈ¨µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£×¢ÈëµãλÓÚδ¹ûÕæµÄPHPÒ³ÃæÉÏ £¬£¬£¬£¬¸ÃÒ³Ãæ¿ÉÒÔʹÓÃGET»òPOST¶ñÒâ¸ºÔØ×÷ΪĿµÄ¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_SaltStack_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-16846/CVE-2020-25592][CNNVD-202011-302/CNNVD-202011-308]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÕýÔÚʹÓÃSaltStackµÄsalt-api½Ó¿ÚÖ´ÐÐí§ÒâÏÂÁ£»£»£»£»£»SaltStackÊÇÒ»¸öÂþÑÜʽÔËάϵͳ £¬£¬£¬£¬ÔÚ»¥ÁªÍø³¡¾°Öб»ÆÕ±éÓ¦Óà £¬£¬£¬£¬ÓÐÒÔÏÂÁ½¸öÖ÷Òª¹¦Ð§£ºÉèÖÃÖÎÀíϵͳ £¬£¬£¬£¬Äܹ»½«Ô¶³Ì½Úµãά»¤ÔÚÒ»¸öÔ¤½ç˵µÄ״̬£¨ÀýÈç £¬£¬£¬£¬È·±£×°ÖÃÌØ¶¨µÄÈí¼þ°ü²¢ÔËÐÐÌØ¶¨µÄЧÀÍ£©ÂþÑÜʽԶ³ÌÖ´ÐÐϵͳ £¬£¬£¬£¬ÓÃÓÚÔÚÔ¶³Ì½ÚµãÉϵ¥¶À»òͨ¹ýí§ÒâÑ¡Ôñ±ê×¼À´Ö´ÐÐÏÂÁîºÍÅÌÎÊÊý¾Ý¡£¡£¸ÃÊÂÎñÓÉÁ½¸ö×éºÏµÄCVEÎó²îµÄʹÓñ¬·¢ £¬£¬£¬£¬Í¨¹ýCVE-2020-25592½á¹¹í§Òâ¡°eauth¡±/¡°token¡±Öµ £¬£¬£¬£¬ÈƹýÉí·ÝÈÏÖ¤£»£»£»£»£»£»Í¨¹ýCVE-2020-16846Ö´ÐÐshell¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_SQL_Server_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0618][CNNVD-202002-496]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS) £¬£¬£¬£¬ÊÇÏÖÔÚÌìÏÂÉÏÆÕ±éʹÓõÄÊý¾Ý¿âÖ®Ò»¡£¡£¸ÃÎó²îÔ´ÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢ËÍÈ«ÐĽṹµÄÇëÇó £¬£¬£¬£¬¿ÉʹÓôËÎó²îÔÚ±¨±íЧÀÍÆ÷ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£

¸üÐÂʱ¼ä£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_PHP·´ÐòÁл¯¹¤Ç©×ÖÌÃÊý¾Ý·¢Ã÷

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

Èô³ÌÐòδ¶ÔÓû§ÊäÈëµÄÐòÁл¯×Ö·û´®¾ÙÐмì²â £¬£¬£¬£¬Ôò¿ÉÄܵ¼Ö¹¥»÷Õß¿ÉÒÔ¿ØÖÆ·´ÐòÁл¯Àú³Ì £¬£¬£¬£¬Í¨¹ýÔÚ²ÎÊýÖÐ×¢ÈëһЩ´úÂë £¬£¬£¬£¬´Ó¶øµÖ´ï´úÂëÖ´ÐÐ £¬£¬£¬£¬SQL×¢Èë £¬£¬£¬£¬Ä¿Â¼±éÀúµÈ²»¿É¿ØÐ§¹û¡£¡£

¸üÐÂʱ¼ä£º

20220708