ÿÖÜÉý¼¶²¼¸æ-2021-10-26

°ä²¼¹¦·ò 2021-10-27

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_QNAP-QTS_ºÅÁî×¢Èë[CVE-2017-7876][CNNVD-201704-779]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

QNAPSystemsQNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬¶àýÌåÀûÓü°°²È«¼à¿ØµÈÖ°ÄÜ¡£QNAPQTS4.2.6build20170517֮ǰµÄ°æ±¾ÖдæÔÚºÅÁî×¢Èë·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶עÈëºÅÁî¡£

¸üй¦·ò£º

20211026

 


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_VMware_vCenter_Server_·þÎñÆ÷¶ËÒªÇóαÔì·ì϶[CVE-2021-21973][CNNVD-202102-1559]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃVMwarevCenterServer·þÎñÆ÷¶ËÒªÇóαÔì·ì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¸Ã·ì϶ԴÓÚVMwarevCenterServer²å¼þÖжÔÓû§ÌṩµÄÊäÈëÑéÖ¤²»µ±£¬Î´¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»·¢ËÍÌØÔìµÄHTTPÒªÇ󣬺ýŪÀûÓ÷¨Ê½ÏòËÁÒâϵͳÌáÒéÒªÇóʵÏÖÄÚÍøÉ¨Ã裬»ñÈ¡ÄÚÍøÐÅÏ¢£¬µ¼ÖÂÐÅϢй¶¡£

¸üй¦·ò£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Jetty_WEB-INF_ÐÅϢй¶·ì϶[CVE-2021-34429]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

EclipseJetty°æ±¾9.4.37-9.4.42¡¢10.0.1-10.0.5ºÍ11.0.1-11.0.5£¬Äܹ»Ê¹ÓÃһЩ±àÂë×Ö·û»ú¹ØÌØÊâµÄURIÀ´½Ó¼ûWEB-INFĿ¼µÄÄÚÈÝ¡£

¸üй¦·ò£º

20211019

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_D-LinkDSL-2640U&DSL-2540U_ºÅÁîÖ´ÐÐ[CVE-2018-5371][CNNVD-201801-545]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

D-LinkDSL-2640UÉ豸£¨¹Ì¼þΪIM_1.00ºÍME_1.00£©ºÍDSL-2540UÉ豸£¨¹Ì¼þΪME_1.00£©ÉϵÄdiag_ping.cmdÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýHTTPGETÒªÇóµÄipaddr×Ö¶ÎÖеÄshellÔª×Ö·ûÖ´ÐÐËÁÒâOSºÅÁî¡£

¸üй¦·ò£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Subrion-CMS_´úÂëÖ´ÐÐ[CVE-2018-19422][CNNVD-201811-628]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

SubrionCMSÊÇSubrionÍŶӿª·¢µÄÒ»Ì×»ùÓÚPHPµÄÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¸Ãϵͳ¿É±»¼¯³Éµ½ÍøÕ¾£¬²¢Ö§³Ö¶àÖÖÀ©´ó²å¼þµÈ¡£SubrionCMS4.2.1°æ±¾ÖеÄ/panel/uploads´æÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ.htaccessÎļþûÓв»ÈݶÔphtºÍpharÎļþµÄÖ´ÐвÙ×÷¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú.pht»ò.pharÎļþÀûÓø÷ì϶ִÐÐËÁÒâµÄPHP´úÂë¡£

¸üй¦·ò£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_OpenMRS_´úÂëÖ´ÐÐ[CVE-2018-19276][CNNVD-201902-602]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OpenMRSÊÇÃÀ¹úOpenMRS¹«Ë¾µÄÒ»Ì׿ªÔ´µÄµç×Ó²¡Àúϵͳ¡£OpenMRSPlatform2.24.0֮ǰ°æ±¾ÖдæÔÚ°²È«·ì϶¡£

¸üй¦·ò£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Billion_5200W-T_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2017-18372][CNNVD-201905-077]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Billion5200W-T·ÓÉÆ÷ÔÚ¹¦·òÉèÖÃÖ°ÄÜÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¸Ã·ì϶λÓÚtools_time.aspÒ³Ãæ£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâºÅÁî²¢Ö´ÐС£

¸üй¦·ò£º

20211026

 

 

ÊÂÎñÃû³Æ£º

UDP_DD-WRT_»º³åÇøÒç¶Âí½Å[CVE-2021-27137]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

DD-WRTÊÇÒ»¸ö»ùÓÚLinuxµÄÎÞÏß·ÓÉÈí¼þ¡£¸Ã·ì϶£¬Í¨¹ý»º³åÇøÒç³ö¿ÉÖ´ÐÐËÁÒâºÅÁµ¼ÖÂÖ÷»úÓб»ÊÕÊܵķçÏÕ¡£

¸üй¦·ò£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Billion_5200W-T_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2017-18369][CNNVD-201905-073]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Billion5200W-T·ÓÉÆ÷ÔÚÔÚadv_remotelog.aspÎļþÖдæÔÚδ¾­Éí·ÝÑéÖ¤µÄºÅÁî×¢Èë¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâºÅÁî²¢Ö´ÐС£

¸üй¦·ò£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_OTRS_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2017-16921][CNNVD-201711-917]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ÔÚOTRS6.0.xÖÁ6.0.1¡¢OTRS5.0.xÖÁ5.0.24ºÍOTRS4.0.xÖÁ4.0.26ÖУ¬ÒÔ´úÀíÉí·ÝµÇ¼OTRSµÄ¹¥»÷ÕßÄܹ»°Ñ³Ö±íµ¥²ÎÊý£¨ÓëPGPÓйأ©²¢ÔÚOTRS»òWeb·þÎñÆ÷Óû§µÄȨÏÞÏÂÖ´ÐÐËÁÒâshellºÅÁî¡£

¸üй¦·ò£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_HPEÖÇÄÜÖÎÀíÖÐÐÄ_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-7184][CNNVD-202010-863]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

HPEIntelligentManagementCenterÊÇÃÀ¹ú»ÝÆÕÆóÒµ¹«Ë¾£¨HewlettPackardEnterprise£¬HPE£©µÄÒ»Ì×ÍøÂçÖÇÄÜÖÎÀíÖÐÐĽâ¾ö¹æ»®¡£¸Ã½â¾ö¹æ»®¿ÉÌṩÕû¸öÍøÂçÁìÓòµÄ¿ÉÊÓÐÔ£¬ÊµÏÖ¶Ô×ÊÔ´¡¢·þÎñºÍÓû§µÄÈ«ÃæÖÎÀí¡£HPEIntelligentManagementCenter(iMC)7.3֮ǰ°æ±¾´æÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚviewbatchtaskresultdetailfact±í°×ʽ˵»°×¢ÈëÔ¶³Ì´úÂëÖ´Ðзì϶¡£

¸üй¦·ò£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_FreePBX°²È«Èƹý·ì϶[CVE-2019-19006][CNNVD-201911-1264]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÀûÓÃFreePBX°²È«Èƹý·ì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£FreePBX£¨Ç°³ÆAsteriskManagementPortal£©ÊÇFreePBXÏîÖ÷ÕÅÒ»Ì×ͨ¹ýGUI£¨»ùÓÚÍøÒ³µÄͼÐλ¯½Ó¿Ú£©ÅäÖÃAsterisk£¨IPµç»°ÏµÍ³£©µÄ¹¤¾ß¡£FreePBX115.0.16.26¼°Ö®Ç°°æ±¾¡¢14.0.13.11¼°Ö®Ç°°æ±¾ºÍ13.0.197.13¼°Ö®Ç°°æ±¾ÖдæÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µÄ½Ó¼û½ÚÔì¡£¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ýÃÜÂëÉí·ÝÑéÖ¤²¢½Ó¼û·þÎñÖ°ÄÜ¡£

¸üй¦·ò£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_D-Link_DIR-859Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2019-17621][CNNVD-201912-1224]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÀûÓÃD-Link_DIR-859Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£D-LinkDIR-859É豸LAN²ãÖгöÏÖδ¾­Éí·ÝÑéÖ¤µÄºÅÁîÖ´Ðзì϶¡£

¸üй¦·ò£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_VMware_NSX_SD-WAN_Edge_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-6961][CNNVD-201805-1140]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃVMware_NSX_SD-WANEdgeµÄ·ì϶½øÐй¥»÷£»VMwareSD-WANEdgeÊÇÒ»¿îÁã½Ó´¥Ê½ÆóÒµ¼¶É豸,¿ÉÄÜÒÔ¾­¹ýÓÅ»¯µÄ·½Ê½Îª×¨ÓÓ×¢¹«¹²»ò»ìºÏÀûÓÃ,ÒÔ¼°ÍÆËãºÍÐé¹¹»¯·þÎñÌṩ°²È«ÏνÓ¡£

¸üй¦·ò£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ZyXEL-CloudCNM-SecuManager_´úÂë×¢Èë[CVE-2020-15348][CNNVD-202006-1754]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ZyxelCNMSecuManager3.1.0ºÍ3.1.1°æ´æÔÚÓ²±àÂë»úÃÜ¡¢Éí·ÝÑéÖ¤ÃÔʧ¡¢ºóÃźÍÔ¶³Ì´úÂëÖ´Ðзì϶¡£Í¨¹ýdelete_cpes_by_ids½øÐдúÂë×¢Èë¿ÉÖ´ÐÐËÁÒâ´úÂ룬·çÏÕÖ÷»ú°²È«¡£

¸üй¦·ò£º

20211026

 

Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_FCKeditor_ASP_½âÎö·ì϶ÉÏ´«¾ç±¾Ö´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃFCKeditor_ASP_½âÎö·ì϶ÉÏ´«¾ç±¾Ö´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£FCKeditorÊÇ¿ªÔ´µÄÍøÒ³±à×ëÆ÷£¬±»¶à¶à´øÓбà×ëÖ°ÄܵÄÍøÕ¾»òÕßCMSʹÓá£FCKeditor´æÔÚFCKeditor_ASP_½âÎö·ì϶ÉÏ´«¾ç±¾Ö´Ðзì϶£¬¹¥»÷ÕßÀûÓô˷ì϶ÉÏ´«ËÁÒâÀàÐÍÎļþ£¬»ñȡָ±êÍøÕ¾µÄwebshell£¬½øÒ»²½»ñÈ¡ÍøÕ¾½ÚÔìȨ¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£

¸üй¦·ò£º

20211026


 

ÊÂÎñÃû³Æ£º

HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅIPÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬ÀûÓÃÁìÓòºÜ¹ã¡£¹¥»÷³É¹¦£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20211026


ɾ³ýÊÂÎñ


1¡¢HTTP_ͨÓÃ_unicodeÈÆ¹ý

2¡¢SMB_»Ø¾ø·þÎñ_Winnuke_¹¥»÷[CVE-1999-0153]