ÿÖÜÉý¼¶²¼¸æ-2021-12-07
°ä²¼¹¦·ò 2021-12-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_°²È«·ì϶_Apache_ShenYu_Admin_δÊÚȨµÇ¼·ì϶_¹¥»÷³¢ÊÔ[CVE-2021-37580][CNNVD-202111-1500] |
°²È«ÀàÐÍ£º | ·ÇÊÚȨ½Ó¼û/ȨÏÞÈÆ¹ý |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃApache_ShenYu_AdminµÄδÊÚȨµÇ¼·ì϶£¬ÈƹýJSONWebToken(JWT)°²È«ÈÏÖ¤£¬Ö±½Ó½øÈëϵͳºó¶Ü |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | TCP_°²È«·ì϶_Dubbo_Hessian2ºÍ̸·´ÐòÁл¯·ì϶[CVE-2021-25641] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚͨ¹ý»ú¹ØserializationidÀ´½øÐÐδÊÚȨ´úÂëÖ´ÐУ¬Í¨¹ýKryo¡¢FST»òÕßnative-javaµÈ°²È«ÐԽϲîµÄÐòÁл¯·½Ê½½øÐз´ÐòÁл¯´úÂëÖ´ÐУ»ApacheDubboÊÇÒ»¸öÉ¢²¼Ê½¿ò¼Ü£¬ÖÂÁ¦ÓÚÌṩ¸ß»úÄÜͨÃ÷»¯µÄRPCÔ¶³Ì·þÎñŲÓù滮£¬ÒÔ¼°SOA·þÎñÖÎÀí¹æ»®¡£ApacheDubboÔÚÏÖʵÀûÓó¡¾°ÖÐÖØÒªÕÆ¹Ü½â¾öÉ¢²¼Ê½µÄÓйØÐèÒª¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | TCP_°²È«·ì϶_Dubbo_Nashorn¾ç±¾Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-30181] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚ¿ÉÄÜÒѾ½ÚÔìÈçZooKeeperÅäÖÃÖÐÐĺó£¬Í¨¹ýÅäÖÃÖÐÐÄÀ´»ú¹Ø¶ñÒâÒªÇó¶ÔDubbo×¢ÈëNashorn¾ç±¾£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ»ApacheDubboÊÇÒ»¸öÉ¢²¼Ê½¿ò¼Ü£¬ÖÂÁ¦ÓÚÌṩ¸ß»úÄÜͨÃ÷»¯µÄRPCÔ¶³Ì·þÎñŲÓù滮£¬ÒÔ¼°SOA·þÎñÖÎÀí¹æ»®¡£ApacheDubboÔÚÏÖʵÀûÓó¡¾°ÖÐÖØÒªÕÆ¹Ü½â¾öÉ¢²¼Ê½µÄÓйØÐèÒª¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Netgear-ProSAFE-Plus_JGS516PE_δÑéÖ¤Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-26919][CNNVD-202010-350] |
°²È«ÀàÐÍ£º | ·ÇÊÚȨ½Ó¼û/ȨÏÞÈÆ¹ý |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCVE-2020-26919·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¹¥»÷³É¹¦£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâºÅÁî¡£NetgearProSAFEPlusJGS516PE/GS116Ev2ÊÇÃÀ¹úÍø¼þ(Netgear)¹«Ë¾µÄÒ»¿î»¥»»»ú¡£NetgearJGS516PEdevices2.6.0.43֮ǰ°æ±¾´æÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚÉ豸ÔÚÖ°Äܼ¶±ðÉÏÊܵ½¶Ìȱ½Ó¼û½ÚÔì¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_WordPress_XSS¾ç±¾×¢Èë·ì϶[CVE-2019-16219][CNNVD-201909-549] |
°²È«ÀàÐÍ£º | XSS¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÉ豸ÔÚÀûÓÃNetgea·ÓÉÆ÷Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£ÔÚNETGEARR7000ÉÏ´æÔÚÒ»¸öÉí·ÝÑéÖ¤ÅÔ·°²È«·ì϶¡£·ì϶ÀûÓóɹ¦ºó£¬Äܹ»rootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_thinkcmf_ºó¶Ü´úÂëÖ´Ðзì϶[CVE-2019-7580][CNNVD-201902-163] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃthinkcmfµÄºó¶Ü´úÂëÖ´Ðзì϶£¬ÔÚ·ÖÀàÖÎÀíÒ³Ãæ´´½¨·ÖÀà±ðºÅʱ£¬Ð´Èë¶ñÒâ´úÂë¡£ThinkCMFÊÇÒ»¿îÖ§³ÖSwooleµÄ¿ªÔ´ÄÚÈÝÖÎÀí¿ò¼Ü(CMF),»ùÓÚThinkPHP¿ª·¢¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_Downloader_APT-C-23_ÏνÓ_±äÖÖ |
°²È«ÀàÐÍ£º | ÏÂÔØÕßľÂí |
ÊÂÎñÃèÊö£º | ¼ì²âµ½APT-C-23ÏÂÔØÆ÷ľÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAPT-C-23ÏÂÔØÆ÷ľÂí¡£APT-C-23ÏÂÔØÆ÷ľÂíÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ÔËÐкó£¬Äܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_DedeCMS_sys_verifies.php_´úÂë×¢Èë·ì϶[CVE-2018-9174][CNNVD-201804-087] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DeDeCMS5.7°æ±¾ÔÚ´æÔÚsys_verifies.php´úÂë×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ¶Ô´«Èë²ÎÊýrefiles¹ýÂ˲»ÑϽ÷£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓô˷ì϶ִÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Phpcms_insdex.php_ǰ̨Getshell |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ip¿ÉÄÜÔÚÀûÓÃPhpcmsǰ̨ע²áÓû§µÄ½çÃæ£¬½øÐÐgetshell²Ù×÷£¬µ«Ä¿Ç°¹æ¶¨ÎÞ·¨ÕýÈ·ÅжÏÊÇ·ñgetshell£»£»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¸ÃÈí¼þѡȡģ¿é»¯¿ª·¢£¬Ö§³Ö¶àÖÖ·ÖÀ෽ʽ£¬Ê¹ÓÃËü¿É·½±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢ÓëÊØ»¤¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Phpcms_insdex.php_ºó¶ÜGetshell |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ip¿ÉÄÜÔÚÀûÓÃPhpcmsºó¶ÜÒ³Ãæ£¬½øÐÐgetshell²Ù×÷£¨Ä¿Ç°¸Ã¹æ¶¨ÎÞ·¨ÕýÈ·ÅжÏÊÇ·ñÒѾgetshell£©£»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¸ÃÈí¼þѡȡģ¿é»¯¿ª·¢£¬Ö§³Ö¶àÖÖ·ÖÀ෽ʽ£¬Ê¹ÓÃËü¿É·½±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢ÓëÊØ»¤¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_DedeCMS_stepselect_main.php_´úÂë×¢Èë·ì϶[CVE-2018-9175][CNNVD-201804-086] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DeDeCMS5.7°æ±¾ÔÚ´æÔÚstepselect_main.php´úÂë×¢Èë·ì϶£¬¸Ã·ì϶ԴÓÚ¶Ô´«Èë²ÎÊýegroup¹ýÂ˲»ÑϽ÷£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓô˷ì϶ִÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_DedeCMS_ºó¶ÜËÁÒâ´úÂëÖ´Ðзì϶[CVE-2018-7700][CNNVD-201803-954] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈݰ䲼¡¢±à×ë¡¢ÖÎÀí¼ìË÷µÅ×ÚÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£DesdevDedeCMS5.7°æ±¾ÖдæÔÚËÁÒâ´úÂëÖ´Ðзì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòtag_test_action.phpÎļþ·¢ËÍ¡®partcode¡¯²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_VMware_Spring_Cloud_Netflix_´úÂëÖ´Ðзì϶[CVE-2021-22053][CNNVD-202111-1645] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | SpringCloudNetflixÊÇÒ»Ì×É¢²¼Ê½·þÎñ¿ò¼ÜµÄ·â×°£¬Ô̺¬·þÎñµÄ·¢ÏÖºÍ×¢²á£¬¸ºÔØÆ½ºâ¡¢¶Ï·Æ÷¡¢REST¿Í»§¶Ë¡¢ÒªÇó·Óɵȡ£¸Ã·ì϶ÊÇÓÉÓÚVMwareSpringCloudÔÚͬʱʹÓÃspring-cloud-netflix-hystrix-dashboardºÍspring-boot-starter-thymeleafµÄÀûÓ÷¨Ê½Ê±£¬¹«¿ªÁËÔÚ½âÎöÊÓͼģ°åÆÚ¼äÖ´ÐÐÒªÇóURIõè¾¶ÖÐÌá½»´úÂëµÄ²½Öè¡£µ±ÔÚ¡®/hystrix/monitor;[user-provideddata]`ÉÏ·¢³öÒªÇóʱ£¬`hystrix/monitor`ºóÃæµÄõè¾¶ÔªËØ½«±»¼ø±ðΪSpringEL±í°×ʽ£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_DedeCMS_Ô¶³Ì´úÂëÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈݰ䲼¡¢±à×ë¡¢ÖÎÀí¼ìË÷µÅ×ÚÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£DedecmsV5.7SP2°æ±¾ÖеÄtpl.phpÖдæÔÚ´úÂëÖ´Ðзì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ý¸Ã·ì϶ÔÚÔö³¤Ð±êÇ©ÖÐÉÏ´«Ä¾Âí£¬»ñÈ¡webshell¡£¸Ã·ì϶ÀûÓñØÒªµÇ¼ºó¶Ü£¬²¢ÇÒºó¶ÜµÄÕË»§È¨ÏÞÊÇÖÎÀíԱȨÏÞ¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_MacCms8.X_Ô¶³Ì´úÂëÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ÷ÈħµçÓ°·¨Ê½(MaccmsPHP)ÊÇÒ»Ì×ѡȡPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÃÀÂúµÄ׳´óÊÓÆµµçӰϵͳ¡£ÃÀÂúÖ§³Ö¶à¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬ÆëÈ«Ãâ·Ñ¿ªÔ´¡£¸Ã·ì϶²úÉúÔÓÉÓÚ¹ýÂ˲»ÑϽ÷µ¼Ö¹¥»÷ÕßÄܹ»Ö±½ÓÔÚÄÚÖÃÄ£°åÖÐ×¢Èë¶ñÒâ´úÂë¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_ÅÀ³æBot½Ó¼û |
°²È«ÀàÐÍ£º | ÍøÒ³ÅÀ³æ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½ÅÀ³æBot¶ÔÖ÷ÕÅIPÖ÷»úµÄweb½Ó¼û,¿ÉÄÜÔÚ¶ÔÖ÷ÕÅIPÖ÷»ú½øÐÐÒ³ÃæÅÀÈ¡¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_TP-LINK_TL-WR840N_EU(V5)_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2021-41653][CNNVD-202111-1211] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | TP-LINKTL-WR840NÊÇÒ»¿îÎÞÏß·ÓÉÆ÷£¬ÐÅ·ÊýΪ13£¬Ö§³ÖVPNÖ°ÄÜ¡£TP-LINKTL-WR840NEU(V5)RouterµÄPINGÖ°ÄÜ´æÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýIPµØÖ·ÖÐÌØÔìµÄÓÐÐ§ÔØºÉÖ´ÐÐÔ¶³ÌºÅÁî¡£ |
¸üй¦·ò£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_º£¿µÍþÊÓIPÉãÏñ»ú/NVR_ºÅÁî×¢Èë·ì϶[CVE-2021-36260][CNNVD-202109-1602] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | º£¿µÍþÊÓIPÉãÏñ»ú/NVRÉ豸¹Ì¼þÖдæÔÚÒ»¸öδÈÏÖ¤ºÅÁî×¢Èë·ì϶£¬ÓÉÓÚ¶ÔÊäÈë²ÎÊýУÑé²»³ä·Ö£¬¹¥»÷ÕßÄܹ»·¢ËÍ´øÓжñÒâºÅÁîµÄ±¨Îĵ½ÊÜÓ°ÏìÉ豸£¬³É¹¦ÀûÓô˷ì϶Äܹ»µ¼ÖºÅÁîÖ´ÐС£º£¿µÍþÊÓÒѰ䲼°æ±¾½¨¸´¸Ã·ì϶£¬¸Ã·ì϶»áÓ°ÏìIPÉãÏñÍ·ºÍNVRÉ豸¹Ì¼þ£¬ÆäÖÐÔ̺¬2021Äê6ÔµÄ×îй̼þÒÔ¼°2006Äê°ä²¼µÄ¹Ì¼þ¡£ |
¸üй¦·ò£º | 20211207 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«É¨Ãè_WEBɨÃèÆ÷ÐÐΪ |
°²È«ÀàÐÍ£º | ÍøÂçɨÃè |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·µÄÖ÷»úÔÚʹÓÃWEBɨÃ蹤¾ß(È磺sqlmap¡¢nessusµÈ)¶ÔÖ÷ÕÅIPµØÖ·½øÐзì϶ɨÃè¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×ö·þÎñɨÃè¡¢·ì϶²âÊԵȡ£Í¨¹ý·ì϶ɨÃ裬Äܹ»×Ô¶¯¼±¾ç̽²âһЩ³£¼û·ì϶Çé¿ö£¬µ±´æÔÚ·ì϶ʱ±ãÓÚºóÐø½øÐÐÀûÓù¥»÷¡£ |
¸üй¦·ò£º | 20211207 |


¾©¹«Íø°²±¸11010802024551ºÅ