ÿÖÜÉý¼¶²¼¸æ-2022-05-03

°ä²¼¹¦·ò 2022-05-03

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_VMware-Workspace-ONE-Access_Ä£°å×¢Èë_ºÅÁîÖ´ÐÐ[CVE-2022-22954][CNNVD-202204-2551]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

VMwareWorkspaceONEAccess£¨ÒÔǰ³ÆÎªVMwareIdentityManager£©Ö¼ÔÚͨ¹ý¶à³É·ÖÉí·ÝÑéÖ¤¡¢Ç°Ìá½Ó¼ûºÍµ¥µãµÇ¼ £¬ÈÃÄúµÄÔ±¹¤¸ü¿ìµØ½Ó¼ûSaaS¡¢WebºÍ±¾»úÒÆ¶¯ÀûÓ÷¨Ê½¡£CVE-2022-22954ÊÇÒ»¸öÄäÃû·þÎñÆ÷Ä£°å×¢Èë·ì϶ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶½øÐÐÔ¶³ÌËÁÒâ´úÂëÖ´ÐС£ÊÜÓ°Ïì°æ±¾ÈçÏ£ºVMwareWorkspaceONEAccessAppliance£¨°æ±¾ºÅ£º20.10.0.0 £¬20.10.0.1 £¬21.08.0.0 £¬21.08.0.1£©VMwareIdentityManagerAppliance£¨°æ±¾ºÅ£º3.3.3 £¬3.3.4 £¬3.3.5 £¬3.3.6£©VMwareRealizeAutomation£¨°æ±¾ºÅ£º7.6£©

¸üй¦·ò£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_WSO2-fileupload_ËÁÒâÎļþÉÏ´«[CVE-2022-29464][CNNVD-202204-3737]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

WSO2-APIManagerÊÇÃÀ¹úWSO2¹«Ë¾µÄÒ»Ì×APIÐÔÃüÖÜÆÚÖÎÀí½â¾ö¹æ»®¡£WSO2-APIManager´æÔÚ°²È«·ì϶ £¬¸Ã·ì϶ÔÊÐíÎÞÏ޶ȵÄÎļþÉÏ´«´Ó¶øÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20220503


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Webshell_AntswordľÂí_

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

Á÷Á¿Öмì²âµ½AntswordµÄ½ÚÔìºÅÁî £¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÔÚ½øÐÐÏνÓÐÐΪ¡£¸ÃWebshellÖØÒªÍ¨¹ýJavaÖÐJSÒýÇæÊµÏÖµÄÒ»¾ä»°Ä¾Âí £¬¸ÄÉÆÁË´«Í³»ú¹Ø×Ö½ÚÂë·½Ê½ÌØµãÏÔÖø £¬payloadÈÝÁ¿´óµÈ±×¶Ë¡£

¸üй¦·ò£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ÒÚÓʵç×ÓÓʼþϵͳ_Ô¶³ÌºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃÒÚÓʵç×ÓÓʼþϵͳͨ¹ýÅú¸ÄcookieÔÚÖ÷ÕÅipÖ÷»úÖ´ÐÐÔ¶³Ì´úÂëÖ´ÐвÙ×÷ £¬ÒÚÓʵç×ÓÓʼþϵͳÊÇÓɱ±¾©ÒÚÖÐÓÊÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾£¨ÒÔϼò³ÆÒÚÓʹ«Ë¾£©¿ª·¢µÄÒ»¿îÃæÏòÖдóÐͼ¯ÍÅÆóÒµ¡¢µ±¾Ö¡¢¸ßУÓû§µÄ¹ú²úÓʼþϵͳ¡£ÒÚÓʵç×ÓÓʼþϵͳѡȡÁË×ÔÖ÷Ñз¢MTAÒýÇæ¡¢É¢²¼Ê½Îļþϵͳ´æ´¢·½Ê½¡¢¶à¶ÔÁлúÔì¡¢ECS´æ´¢×Óϵͳ¡¢CacheϵͳµÈ¶àÏîÖ÷Ìâ¼¼Êõ £¬ÌṩÁË·á˶µÄÓʼþÖ°ÄÜ¡£

¸üй¦·ò£º

20220503


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_TamronOS-IPTVϵͳ_ËÁÒâºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

TamronOSIPTV/VODϵͳÊÇÒ»Ì×»ùÓÚLinuxÄں˿ª·¢µÄ¿í´øÔËÓªÉÌ¡¢¾Æµê¡¢Ñ§ÌÃÖ±²¥µã²¥Ò»Ìå½â¾ö¹æ»®¡£TamronOSIPTVϵͳapi/ping´æÔÚËÁÒâºÅÁîÖ´Ðзì϶ £¬¹¥»÷Õßͨ¹ý·ì϶Äܹ»Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220503


ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_BillGates_½ÚÔìºÅÁî

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½BillGatesµÄC&C·þÎñÆ÷ÊÔͼ·¢ËͽÚÔìºÅÁî¸øBillGates £¬Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçBillGates¡£BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂç £¬ÖØÒªÖ°ÄÜÊÇÕë¶ÔÖ¸¶¨Ö¸±ê½øÐÐDDoS¹¥»÷¡£

¸üй¦·ò£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_PhpTax_pfilez²ÎÊý_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

PhpTax0.8°æ±¾ÖдæÔÚÒ»¸öÔ¶³Ì´úÂë×¢Èë·ì϶ £¬¸Ã·ì϶ԴÓÚÔÚÌìÉúPDFʱ £¬drawimage.phpÖеÄicondrawpng()º¯ÊýÎÞ·¨ÕýÈ·´¦ÖÃpfilez²ÎÊý £¬¸Ã²ÎÊý½«ÔÚexec()Óï¾äÖÐʹÓ᣹¥»÷ÕßÄܹ»Í¨¹ýÔÚpfilez²ÎÊý×¢Èë¶ñÒâÄÚÈÝʵÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20220503


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_MobileIron_MDM_·´ÐòÁл¯·ì϶[CVE-2020-15505][CNNVD-202007-291]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃMobileIron_MDMµÄ·´ÐòÁл¯·ì϶ £¬¸Ã·ì϶µÄ³ÉÒòÊÇMobileIron_MDMʹÓÃÁËHessianºÍ̸µÄJavaÖеÄËÁÒâ·´ÐòÁл¯¡£MobileIronÊÇÈ«Çòµ±ÏÈÇÒ·¢Õ¹×îѸ¿ìµÄÒÆ¶¯IT½â¾ö¹æ»®³§ÉÌÖ®Ò» £¬ÔÚÈ«ÇòÓнü20000¼Ò¹«Ë¾Ê¹ÓÃMobileIronµÄÒÆ¶¯É豸ÖÎÀí½â¾ö¹æ»®£¨MDM£©¡£

¸üй¦·ò£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_PHPCMS_v2008_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-19127][CNNVD-201811-248]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃPHPCMS_v2008ËÁÒâ´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ £¬¸Ã·ì϶ÀûÓÃtype.phpÎļþ»ú¹Ø¶ñÒ⻺´æÎļþ £¬½Ó¼û¸Ã»º´æÎļþÄܹ»»ñÈ¡Óû§È¨ÏÞ¡£PHPCMSÊÇ¿ªÔ´µÄÕûվϵͳ¡£PHPCMS´æÔÚPHPCMS_v2008ËÁÒâ´úÂëÖ´Ðзì϶ £¬¹¥»÷ÕßÀûÓô˷ì϶ÇÔÈ¡Ãô¸ÐÐÅÏ¢ £¬»ñÈ¡Êý¾Ý¿âºÍÖÎÀíԱȨÏÞ¡£

¸üй¦·ò£º

20220503

 

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Netlink_GPON·ÓÉÆ÷ºÅÁî×¢Èë·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Netlink-GPON·ÓÉÆ÷µÄWeb·þÎñ´æÔÚºÅÁî×¢Èë·ì϶ £¬¹¥»÷Õß¿Éͨ¹ýÏòÒªÇóÌåÖеÄÌØ¶¨µØÎ»²åÈë¶ñÒâÔØºÉ £¬Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_ÁéͨOA_ËÁÒâÎļþÉÏ´«/ÎļþÔ̺¬·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ÁéͨOAÊÇÒ»Ìװ칫ϵͳ¡£ÓÉÓÚÁéͨOAÖдæÔÚµÄÁ½Ã¶·ì϶(ÎļþÉÏ´«·ì϶ £¬ÎļþÔ̺¬·ì϶) £¬¹¥»÷Õß¿Éͨ¹ýÕâÁ½Ã¶·ì϶ʵÏÖÔ¶³ÌºÅÁîÖ´ÐС£/ispirit/im/upload.php´æÔÚÈÆ¹ýµÇ¼(ËÁÒâÎļþÉÏ´«·ì϶) £¬½áºÏgateway.php´¦´æÔÚµÄÎļþÔ̺¬·ì϶ £¬×îÖÕµ¼ÖÂgetshell¡£

¸üй¦·ò£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ExifTool_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-22204]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ExifToolÊÇÒ»¸ö¶ÀÁ¢ÓÚÆ½Ì¨µÄPerl¿â £¬Ò²ÓÐÒ»¸öºÅÁîÐÐÀûÓ÷¨Ê½ £¬ÓÃÓÚ¶ÁÈ¡ £¬Ð´ÈëºÍ±à×ë¸÷ÀàÎļþÖеÄÔªÐÅÏ¢¡£¸Ã·ì϶ÊÇÓÉÓÚExifTool°æ±¾7.44°æ±¾ÖдæÔÚ¶ÔDjVuÎļþÌåʽµÄÊý¾Ý´¦Öò»µ±¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚº¬Óзì϶°æ±¾µÄExifTool¿âµÄÀûÓ÷þÎñÆ÷»òÕßÀûÓ÷¨Ê½Ï £¬»ú¹Ø¶ñÒâDjVuÎļþ £¬·þÎñÆ÷»òÕßÀûÓ÷¨Ê½Ô¶³Ì±¾µØ½âÎö´ËÎļþ £¬µ¼ÖÂËÁÒâ´úÂëÖ´ÐÐ £¬×îÖÕ»ñÈ¡·þÎñÆ÷×î¸ßȨÏÞ¡£

¸üй¦·ò£º

20220503