ÿÖÜÉý¼¶²¼¸æ-2022-02-15

°ä²¼¹¦·ò 2022-02-15

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_CactiÔ¶³Ì´úÂëÖ´ÐÐ[CVE-2020-8813][CNNVD-202002-1075]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

CactiÔÚÓ¢ÎÄÖеÄÒâ˼ÊÇÉñÏÉÕÆµÄÒâ˼ £¬CactiÊÇÒ»Ì×»ùÓÚPHP,MySQL,SNMP¼°RRDTool¿ª·¢µÄÍøÂçÁ÷Á¿¼à²âͼÐηÖÎö¹¤¾ß¡£Ëüͨ¹ýsnmpgetÀ´»ñÈ¡Êý¾Ý £¬Ê¹ÓÃRRDtool»æ»­Í¼ÐÎ £¬²¢ÇÒÄãÆëÈ«Äܹ»²»±ØÒªÏàʶRRDtool¸´ÔӵIJÎÊý¡£ÔÚCacti1.2.8µÄ°æ±¾ÖÐ £¬¹¥»÷ÕßÄܹ»Í¨¹ýgraph_realtime.php¡±Ò³ÃæÆôÓ᰷ÿ͡±Ò³Ãæ £¬²¢Í¨¹ýÔÚcookieÖлú¹Ø¶ñÒâ´úÂë £¬Ö´ÐÐÔ¶³ÌºÅÁî¡£

¸üй¦·ò£º

20220215

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ÈýÁâsmartRTU_²Ù×÷ϵͳºÅÁî×¢Èë·ì϶[CVE-2019-14931][CNNVD-201910-1535]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

MitsubishiElectricsmartRTUÊÇÈÕ±¾MitsubishiElectric¹«Ë¾µÄÒ»¿îÖÇÄÜÔ¶³ÌÖն˵¥Ôª£¨RTU£©¡£IneaME-RTUÊÇ˹ÂåÎÄÄáÑÇInea¹«Ë¾µÄÒ»¿îÖÇÄÜÍ¨Ñ¶Íø¹Ø²úÆ·¡£MitsubishiElectricsmartRTU2.02¼°Ö®Ç°°æ±¾ºÍINEAME-RTU3.0¼°Ö®Ç°°æ±¾ÖдæÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£¸Ã·ì϶ԴÓÚ±í²¿ÊäÈëÊý¾Ý»ú¹Ø²Ù×÷ϵͳ¿ÉÖ´ÐкÅÁî¹ý³ÌÖÐ £¬ÍøÂçϵͳ»ò²úƷδÕýÈ·¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ºÅÁîµÈ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨²Ù×÷ϵͳºÅÁî¡£

¸üй¦·ò£º

20220215

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Rejetto_HTTPFileServer_ParserLib.pas´úÂë×¢Èë·ì϶[CVE-2014-6287]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÀûÓÃRejettoHTTPFileServerÖдæÔڵĴúÂë×¢Èë·ì϶½øÐй¥»÷µÄÐÐΪ¡£RejettoHTTPFileServerÊÇÒ»¿îרΪÓ×ÎÒÓû§ËùÉè¼ÆµÄHTTPÎļþ·þÎñÆ÷ £¬ËüÌṩÐé¹¹µµ°¸ÏµÍ³ £¬Ö§³ÖÐÂÔö¡¢ÒƳýÐé¹¹µµ°¸×ÊÁϼеÈ¡£RejettoHTTPFileServer2.3c¼°Ö®Ç°°æ±¾ÖеÄparserLib.pasÎļþÖеġ®findMacroMarker¡¯º¯ÊýÖдæÔÚ°²È«·ì϶ £¬¸Ã·ì϶ԴÓÚparserLib.pasÎļþûÓÐÕýÈ·´¦ÖÿÕ×Ö½Ú¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúËÑË÷²Ù×÷Öеġ®%00¡¯ÐòÁÐÀûÓø÷ì϶ִÐÐËÁÒⷨʽ¡£ÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220215


ÊÂÎñÃû³Æ£º

HTTP_Java_WEBÀûÓÃÅäÖÃÎļþ½Ó¼û

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚ¶ÔÖ÷ÕÅÖ÷»ú½øÐÐHTTP_Java_WEBÀûÓÃÅäÖÃÎļþ½Ó¼û¡£ÔÚÃýÎóÅäÖõÄÇé¿öÏ £¬WEBÀûÓÃÅäÖÃÎļþµÈÃô¸ÐÎļþ¶³öÔÚWEBõè¾¶ÖÐ £¬Í¨¹ý½Ó¼ûÕâЩÎļþ £¬ºÚ¿ÍÄܹ»»ñÈ¡ÍøÕ¾ÅäÖõÈÐÅÏ¢¡£³¢ÊÔ½Ó¼ûwebÀûÓÃÅäÖÃÎļþͨ³£Îª·¢Æð¹¥»÷ǰµÄÐÅÏ¢ÍøÂçÐÐΪ¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£

¸üй¦·ò£º

20220215


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚ̽²âÖ÷ÕÅipÖ÷»úÖпÉÄܶ³öÔÚ±íµÄÃô¸ÐÎļþ¡£

¸üй¦·ò£º

20220215

 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃÊÂÎñ_·¢ÏÖÂÅ´Îunicode±àÂëÐÐΪ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

JavaĬÈϵıàÂ뷽ʽΪUnicode £¬ÔÚjava˵»°ºÍ²¿ÃÅ.net·¨Ê½ÖÐ £¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£ÂÅ´Îunicode±àÂë¿ÉÄÜΪ¹¥»÷Õß³¢ÊÔÈÆ¹ý¼ì²âÉ豸µÄÐÐΪ¡£

¸üй¦·ò£º

20220215

 

ÊÂÎñÃû³Æ£º

HTTP_µÇ¼ʧ°Ü

°²È«ÀàÐÍ£º

°²È«Éó¼Æ

ÊÂÎñÃèÊö£º

¼ì²âµ½HTTPµÇ¼ÈÏ֤ʧ°ÜµÄÐÐΪ

¸üй¦·ò£º

20220215