ÿÖÜÉý¼¶²¼¸æ-2022-07-08

°ä²¼¹¦·ò 2022-07-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Confluence_ËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2019-3396][CNNVD-201903-909]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ConfluenceÊÇ¿îÆóҵ֪ʶ¿âÈí¼þ¡£ÆäÖÐConfluenceServerºÍDataCenter²úÆ·ÖÐʹÓõÄÓ×¹¤¾ßÏÎ½ÓÆ÷widgetconnecter×é¼þ£¨°æ±¾<=3.1.3£©ÖдæÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_UCM6202_1.0.18.13Ô¶³ÌºÅÁî×¢Èë·ì϶[CVE-2020-5722][CNNVD-202003-1337]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

GrandstreamUCM6200ϵÁеÄHTTP½Ó¿ÚÈÝÒ×Êܵ½¾«ÐÄÉè¼ÆµÄHTTPÒªÇóδ¾­Éí·ÝÑéÖ¤µÄÔ¶³ÌSQL×¢ÈëµÄ¹¥»÷¡£¹¥»÷ÕßÄܹ»Ê¹Óô˷ì϶ÒÔrootÉí·ÝÔÚ1.0.19.20֮ǰµÄ°æ±¾ÖÐÖ´ÐÐshellºÅÁî £¬»òÔÚ1.0.20.17֮ǰµÄ°æ±¾ÖеÄÃÜÂ븴ԭµç×ÓÓʼþÖÐ×¢ÈëHTML¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Netgear_R7000_RouterÔ¶³ÌºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

NetgearR7000,¹Ì¼þ°æ±¾1.0.7.2_1.1.93ÒÔ¼°¸üÔçÆÚ°æ±¾ £¬R6400¹Ì¼þ°æ±¾1.0.1.6_1.0.4ÒÔ¼°¸üÔçÆÚ°æ±¾,Ô̺¬Ò»¸öÔ̺¬ËÁÒâºÅÁî×¢Èë·ì϶.¹¥»÷Õß¿ÉÄÜÓÕʹÓû§½Ó¼ûÇɾ¡ÐÄÀí¹¹½¨µÄwebÕ¾µã £¬´Ó¶øÒÔ¸ùÓû§È¨ÏÞÔÚÊÜÓ°ÏìµÄ·ÓÉÆ÷ÉÏÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_shadowÄÚÈÝÎļþ»ØÏÔ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö:

·¢ÏÖÓÐetc/shadowÎļþµÄ»ØÏÔÒ³Ãæ

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕß £¬ÔËÐкó £¬Äܹ»ÏÂÔØÆäËü¶ñÒâÑù±¾ £¬ÈçºóÃŵÈ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_³¢ÊÔÏνӿó³Ø(BEAM)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½ÍÚ¿óľÂíÊÔͼÏνÓÔ¶³Ì¿ó³Ø·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ £¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´ £¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£BeamÊÇ»ùÓÚMimbleWimbleºÍ̸¿ª·¢µÄ¼ÓÃÜÇ®±Ò £¬ÓµÓÐÇ¿ÒþÖÔÐÔ¡¢´úÌæÐÔºÍÀ©´óÐÔ¡£BeamËùÓÐÂòÂô¶¼Ä¬ÈÏÊÇ˽ÃܵÄ¡£Ð½ڵã²ÎÓëÍøÂçÎÞÐèͬ²½Õû¸öÂòÂôº¹Çà £¬Äܹ»ÒªÇóͬ²½Ö»Ô̺¬ÏµÍ³×´Ì¬µÄѹËõº¹Çà¼Í¼ºÍÇø¿éÍ· £¬´Ó¶øÊµÏÖ¼±¾çͬ²½¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ÏÎ½Ó¿ó³Ø³É¹¦(BEAM)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½ÍÚ¿óľÂíÏνÓÔ¶³Ì¿ó³Ø·þÎñÆ÷³É¹¦µÄÐÐΪ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ £¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´ £¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£BeamÊÇ»ùÓÚMimbleWimbleºÍ̸¿ª·¢µÄ¼ÓÃÜÇ®±Ò £¬ÓµÓÐÇ¿ÒþÖÔÐÔ¡¢´úÌæÐÔºÍÀ©´óÐÔ¡£BeamËùÓÐÂòÂô¶¼Ä¬ÈÏÊÇ˽ÃܵÄ¡£Ð½ڵã²ÎÓëÍøÂçÎÞÐèͬ²½Õû¸öÂòÂôº¹Çà £¬Äܹ»ÒªÇóͬ²½Ö»Ô̺¬ÏµÍ³×´Ì¬µÄѹËõº¹Çà¼Í¼ºÍÇø¿éÍ· £¬´Ó¶øÊµÏÖ¼±¾çͬ²½¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_»ñÈ¡ÍÚ¿ó¹¤×÷(BEAM)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½´Ó¿ó³ØÏò¿ó»úÏ·¢ÍÚ¿ó¹¤×÷µÄÐÐΪ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ £¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´ £¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£BeamÊÇ»ùÓÚMimbleWimbleºÍ̸¿ª·¢µÄ¼ÓÃÜÇ®±Ò £¬ÓµÓÐÇ¿ÒþÖÔÐÔ¡¢´úÌæÐÔºÍÀ©´óÐÔ¡£BeamËùÓÐÂòÂô¶¼Ä¬ÈÏÊÇ˽ÃܵÄ¡£Ð½ڵã²ÎÓëÍøÂçÎÞÐèͬ²½Õû¸öÂòÂôº¹Çà £¬Äܹ»ÒªÇóͬ²½Ö»Ô̺¬ÏµÍ³×´Ì¬µÄѹËõº¹Çà¼Í¼ºÍÇø¿éÍ· £¬´Ó¶øÊµÏÖ¼±¾çͬ²½¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ľÂí_CPUMiner_ÍÚ¿ó½ÚÔìºÅÁîͨѶ_¿ó»úÉèÖù²ÏíÖ¸±ê(BTC/LTC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½¿ó»úÏò¿ó³ØÅú×¢¶Ô¹²ÏíÖ¸±êµÄÆ«ºÃµÄÐÐΪ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCPUMinerÍÚ¿óľÂí¡£CPUMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ £¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´ £¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_H2database_console_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÀûÓÃh2consoleµÄĬÈÏ·ÓÉÉèÖÃΪ±í²¿¶ñÒâjndi·þÎñÆ÷µØÖ·¡£H2DatabaseÊÇÒ»¸ö¿ªÔ´µÄǶÈëʽÊý¾Ý¿âÒýÇæ £¬Ñ¡È¡java˵»°±àд £¬²»ÊÜÆ½Ì¨µÄÏÞ¶È £¬Í¬Ê±H2DatabaseÌṩÁËÒ»¸ö¼«¶È·½±ãµÄweb½ÚÔį̀ÓÃÓÚ²Ù×÷ºÍÖÎÀíÊý¾Ý¿âÄÚÈÝ¡£H2Database»¹Ìṩ¼æÈÝģʽ £¬Äܹ»¼æÈÝһЩÖ÷Á÷µÄÊý¾Ý¿â £¬Òò¶øÑ¡È¡H2Database×÷Ϊ¿ª·¢ÆÚµÄÊý¾Ý¿â¼«¶È·½±ã¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_CMS_Joomla´úÂëÖ´ÐÐ[CVE-2020-10238]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

Joomla!ÊÇÃÀ¹úOpenSourceMattersÍŶӵÄÒ»Ì×ʹÓÃPHPºÍMySQL¿ª·¢µÄ¿ªÔ´¡¢¿çƽ̨µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£JoomlaÊÇÒ»Ì×ÄÚÈÝÖÎÀíϵͳ £¬ÊÇʹÓÃPHP˵»°¼ÓÉÏMYSQLÊý¾Ý¿âËù¿ª·¢µÄÈí¼þϵͳ¡£ÓÉÓÚjoomlaȨÏÞ·ÖÅä²»ºÏÀíµ¼ÖÂÖÎÀíԱȨÏÞÕ˺ſɶÔÓйØphpÒ³Ãæ½øÐбà×ë £¬²åÈëÓйضñÒâ´úÂëµ¼ÖºÅÁîÖ´ÐС£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Apache_HTTP_Server_õè¾¶´©Ô½·ì϶[CVE-2021-42013][CNNVD-202110-413]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚ³¢ÊÔ¶ÔÖ÷ÕÅIPÖ÷»úͨ¹ýApacheHTTPServer½øÐÐĿ¼´©Ô½·ì϶¹¥»÷³¢ÊÔµÄÐÐΪ¡£Apache_HTTP_ServerÊÇApache»ù´¡Ê¢¿ªµÄÊ¢ÐеÄHTTP·þÎñÆ÷¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Gogs_session_δÊÚȨ½Ó¼û[CVE-2018-18925][CNNVD-201811-049]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

gogsÊÇÒ»¿î¼«Ò״µÄ×ÔÖ÷Git·þÎñƽ̨ £¬ÓµÓÐÒ××°Öᢿçƽ̨¡¢ÇáÁ¿¼¶µÈÌØµã £¬Ê¹ÓÃÕß¶à¶à¡£Æä0.11.66¼°ÒÔǰ°æ±¾ÖÐ £¬£¨go-macaron/session¿â£©Ã»ÓжÔsessionid½øÐÐУÑé £¬¹¥»÷ÕßÀûÓöñÒâsessionid¼´¿É¶ÁÈ¡ËÁÒâÎļþ £¬Í¨¹ý½ÚÔìÎļþÄÚÈÝÀ´½ÚÔìsessionÄÚÈÝ £¬½ø¶øµÇ¼ËÁÒâÕË»§¡£¹¥»÷Õ߿ɵǽËÁÒâÕ˺ÅÔ̺¬ÖÎÀíÔ¹ØËºÅ £¬Í¬Ê±¿ÉÀûÓÃgithooksÖ´ÐÐËÁÒâºÅÁî £¬Í¬Ê±´æÔÚÑϳÁµÄԽȨºÍºÅÁîÖ´ÐÐÎÊÌâ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SaltStack_δÊÚȨ½Ó¼û[CVE-2021-25281][CNNVD-202102-1696]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

SaltAPIwheel_asyncδÊÚȨ½Ó¼û·ì϶ÖÐ £¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâÒªÇó £¬Í¨¹ýwheel_asyncŲÓÃmasterµÄwheel²å¼þ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉÃô¸ÐÎļþÏÂÔØ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

·¢ÏÖÃô¸ÐÎļþÏÂÔØÐÐΪ £¬ÈçÏÂÔØ±¸·ÝÎļþ £¬·¨Ê½Ô´Âë £¬SQLÎļþ £¬ÅäÖÃÎļþµÈÕâÀàÐÐΪ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉ¿ÉÖ´ÐÐÎļþÉÏ´«

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÖ÷»ú´æÔÚÉÏ´«¿ÉÒÉwebshellµ½Ö÷ÕÅipÖ÷»úµÄÐÐΪ

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Java_Shellcode±¾µØ¹ý³Ì×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃWindowsVirtualMachineÀàÖеÄenqueue²½Öè¶ÔÖ÷ÕÅÖ÷»ú½øÐÐJava±¾µØ¹ý³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄpayload £¬Ê¹ÓöñÒâÀà½øÇ°¹ý³Ì×¢ÈëÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_CouchDB_´¹Ö±Ô½È¨·ì϶[CVE-2017-12635][CNNVD-201711-487]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â £¬×¨Ò»ÓÚÒ×ÓÃÐԺͳÉΪ¡±Æëȫӵ±§webµÄÊý¾Ý¿â¡±¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢Ìåʽ £¬JavaScript×÷Ϊ²éÎÊ˵»° £¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£µ¼Ö·ì϶µÄÔ­ÒòÊÇErlangºÍJavaScript £¬¶ÔJSON½âÎö·½Ê½µÄ·ÖÆç £¬¶ÔÓÚ³Á¸´µÄ¼üErlang»á´æ´¢Á½¸öÖµ £¬¶øJavaScriptÖ»´æ´¢µÚ¶þ¸öÖµ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Discuz!ML_V3.X_ºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

Discuz!MLϵͳ¶ÔcookieÖнӹܵÄlanguage²ÎÊýÄÚÈÝδ¹ýÂË £¬µ¼ÖÂ×Ö·û´®Æ´½Ó £¬´Ó¶øÖ´ÐÐphp´úÂë¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_OpenSSL_·´µ¯shellºÅÁî×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÏòÖ÷ÕÅÖ÷»ú½øÐÐOpenSSL·´µ¯shellºÅÁî×¢Èë¹¥»÷¡£·´µ¯ÏνÓ £¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨·þÎñ¶Ë £¬Êܺ¦ÕßÖ÷»ú×Ô¶¯Ïνӹ¥»÷ÕߵķþÎñ¶Ë·¨Ê½¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞ²»¼°¡¢¶Ë¿Ú±»Õ¼ÓõÈÇé¾°¡£¹¥»÷Õß¹¥»÷³É¹¦ºóÄܹ»Ô¶³ÌÖ´ÐÐϵͳºÅÁî¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_CMS-Phpcms:V9.5.8_ºó¶Ügetshell

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCMS-Phpcms:V9.5.8ºó¶ÜËÁÒâ´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ £¬¸Ã·ì϶ÀûÓÃcontent.phpÎļþ»ú¹Ø¶ñÒâpayload £¬´Ó¶øÔì³É´úÂëÖ´ÐС£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Covenant_ÏνÓC2·þÎñÆ÷_ÉÏ´«ÐÅÏ¢»òºÅÁî½»»¥

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

CovenantÊÇÒ»¸ö.NET¿ª·¢µÄC2(commandandcontrol)¿ò¼Ü £¬Ê¹ÓÃ.NETCoreµÄ¿ª·¢»·¾³ £¬²»½öÖ§³ÖLinux £¬MacOSºÍWindows £¬»¹Ö§³ÖdockerÈÝÆ÷¡£CovenantÖ§³Ö¶¯Ì¬±àÒë £¬¿ÉÄܽ«ÊäÈëµÄC#´úÂëÉÏ´«ÖÁC2Server £¬»ñµÃ±àÒëºóµÄÎļþ²¢Ê¹ÓÃAssembly.Load()´ÓÄÚ´æ½øÐмÓÔØ¡£¸ÃÊÂÎñÅú×¢ £¬CovenantµÄÌìÉúÎïGruntsľÂíºóÃÅÔÚÏνÓC2·þÎñÆ÷½øÐÐÉÏ´«ÐÅÏ¢»òºÅÁî½»»¥¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Alibaba-Canal-configÔÆÃÜÔ¿ÐÅϢй¶·ì϶

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö:

canalÊǰ¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌâ £¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄµØÖ·½Ó¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_laravel_pop3ÀûÓÃÁ´¹¥»÷[CVE-2022-31279][CNNVD-202206-671]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

Laravel9.1.8ÔÚ´¦Öù¥»÷Õß½ÚÔìµÄ·´ÐòÁл¯Êý¾Ýʱ £¬ÔÊÐíͨ¹ýIlluminate\Broadcasting\PendingBroadcast.phpÖеÄ__destructºÍFaker\Generator.phpÖеÄ__callÖеÄδÐòÁл¯µ¯³öÁ´Ö´ÐÐÔ¶³Ì´úÂëÖ´ÐÐ(RCE)¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖÐ £¬Ò»Ð©Ê¾ÀýDAGûÓÐÕýÈ·ËãÕÊÓû§ÌṩµÄ²ÎÊý £¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSºÅÁî×¢ÈëµÄÓ°Ïì¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.7.1ÒÔÏÂ_·ÇÊÚȨ½Ó¼û[CVE-2020-17523][CNNVD-202102-238]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ApacheShiroÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü £¬ËüÄܹ»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£Ä¿Ç°³£¼û¼¯³ÉÓÚ¸÷ÀàÀûÓÃÖнøÐÐÉí·ÝÑéÖ¤ £¬ÊÚȨµÈ¡£¶ÔÓÚApacheShiro1.7.1֮ǰµÄ°æ±¾ £¬µ±½«ApacheShiroÓëSpring½ÚÔìÆ÷һ·ʹÓÃʱ £¬¹¥»÷ÕßÌØÔìÒªÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SangforEDR²»¸ßÓÚ3.2.19_·ÇÊÚȨ½Ó¼û

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÊÔͼͨ¹ýSangforEDRµÄ·ÇÊÚȨ½Ó¼û·ì϶ £¬ÊäÈëuser=admin¼´¿É»ñÈ¡Óû§È¨ÏÞ¡£SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÕÛ·þ¹«Ë¾ÌṩµÄÒ»Ì×Öն˰²È«½â¾ö¹æ»®¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_CLTPHP-v5.8_ºó¶ÜËÁÒâÎļþɾ³ý

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

CLTPHPÊÇ»ùÓÚThinkPHP5¿ª·¢ £¬ºó¶ÜѡȡLayui¿ò¼ÜµÄÄÚÈÝÖÎÀíϵͳ¡£CLTPHP5.8¼°Ö®Ç°°æ±¾´æÔÚºó¶ÜËÁÒâÎļþɾ³ý·ì϶ £¬Í¨¹ý»ú¹Ø¶ñÒâpayload¹¥»÷Õß¿Éɾ³ýϵͳÖеÄËÁÒâÎļþ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_AspectJWeaver_Java·´ÐòÁл¯ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃaspectjweaverµÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁË´æÔÚaspectjweaver:1.9.2,commons-collections:3.2.2µÄÒÀÀµ £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Gila-CMS-2.0.0_ÎļþдÈë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

GilaCMS2.0.0°æ±¾¼°ÒÔϰ汾»á½«User-AgentÖеÄÄÚÈÝдÈëµ½GSESSIONIDcookieÖÐÖ¸¶¨µÄÎļþÖÐ £¬Òò¶øÄܹ»ÀûÓÃÕâµã½«webshellдÈëµ½phpÎļþÖÐ £¬Ôì³ÉËÁÒâ´úÂëÖ´ÐС£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶û°²È«ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_service.php_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÉϺ£¸ñ¶û°²È«ÈÏÖ¤Íø¹ØÖÎÀíϵͳ´æÔÚÒ»¸öºÅÁîÖ´Ðзì϶ £¬¸Ã·ì϶ԴÓÚservice.phpÖжԴ«ÈëµÄservice_path²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷ £¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÒªÇó £¬Ô¶³ÌÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶û°²È«ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_PrivManager.php_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÉϺ£¸ñ¶û°²È«ÈÏÖ¤Íø¹ØÖÎÀíϵͳ´æÔÚÒ»¸öºÅÁîÖ´Ðзì϶ £¬¸Ã·ì϶ԴÓÚPrivManager.phpÖжԴ«ÈëµÄmode_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷ £¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÒªÇó £¬Ô¶³ÌÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÉϺ£¸ñ¶û°²È«ÈÏÖ¤Íø¹ØÖÎÀíϵͳ_SetVer.php_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÉϺ£¸ñ¶û°²È«ÈÏÖ¤Íø¹ØÖÎÀíϵͳ´æÔÚÒ»¸öºÅÁîÖ´Ðзì϶ £¬¸Ã·ì϶ԴÓÚSetVer.phpÖжԴ«ÈëµÄversion_type²ÎÊýÄÚÈݹýÂ˲»ÑϽ÷ £¬¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÒªÇó £¬Ô¶³ÌÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_PHP-8.1.0-dev_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

PHP8.1.0-devÓÚ2021Äê3ÔÂ28ÈÕ°ä²¼µÄ°æ±¾ÖдæÔÚºóÃÅ £¬Í¨¹ýUser-AgenttÍ·Äܹ»Ö´ÐÐËÁÒâ´úÂë»òºÅÁî

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring3_Java·´ÐòÁл¯ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃSpring3µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËspring-tx:5.2.3.RELEASE,spring-context:5.2.3.RELEASE,javax.transaction-api:1.2 £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JRMPListener_Java·´ÐòÁл¯ÀûÓÃÁ´¹¥»÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃJRMPListenerµÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Ææ°²ÐÅÖն˰²È«ÖÎÀíϵͳÌìÇæÔ½È¨½Ó¼û·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½¹¥»÷ÕßÔÚÀûÓÃÌìÇæÇ°Ì¨Ö±½Ó½Ó¼ûĿ¼¿É»ñÈ¡Êý¾Ý¿âÓйØÐÅÏ¢

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Netgear-»¥»»»ú_ºÅÁî×¢Èë[CVE-2021-33514][CNNVD-202105-1401]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

É豸Ôڽӹܵ½setup.cgi?token=';$HTTP_USER_AGENT;'Ò»ÀàÊý¾ÝÊ £¬ÓÉÓÚδ½øÐа²È«¹ýÂË £¬´æÔÚ±»¹¥»÷Õßͨ¹ýÐîÒâ»ú¹ØµÄ¶ñÒâÊý¾Ý¹¥»÷ £¬µ¼ÖÂÔÚÉ豸ÉÏÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220708


Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Ãô¸ÐÐÅϢй¶_³£¼ûÃô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚ̽²âÖ÷ÕÅipÖ÷»úÖпÉÄܶ³öÔÚ±íµÄÃô¸ÐÎļþ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_Oracle_WebLogic_·´ÐòÁл¯·ì϶[CVE-2019-2725/CVE-2019-2729]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

´Ë·ì϶ÊÇÓÉÓÚÀûÓÃÔÚ´¦Ö÷´ÐòÁл¯ÊäÈëÐÅϢʱ´æÔÚȱµã £¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢Ë;«ÐÄ»ú¹ØµÄ¶ñÒâHTTPÒªÇó £¬ÓÃÓÚ»ñµÃÖ¸±ê·þÎñÆ÷µÄȨÏÞ £¬²¢ÔÚδÊÚȨµÄÇé¿öÏÂÖ´ÐÐÔ¶³ÌºÅÁî £¬×îÖÕ»ñÈ¡·þÎñÆ÷µÄȨÏÞ¡£CVE-2019-2729ÊÇCVE-2019-2725µÄÈÆ¹ý¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_DolphinScheduler_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-11974][CNNVD-202012-1358]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃApacheDolphinSchedulerµÄJDBC¿Í»§¶Ë½øÐз´ÐòÁл¯²Ù×÷½ø¶øµ¼ÖÂÔ¶³Ì´úÖ´ÐС£ApacheDolphinScheduler(Incubator,Ô­EasyScheduler)ÊÇÒ»¸öÉ¢²¼Ê½Êý¾Ý¹¤×÷Á÷¹¤×÷µ÷¶Èϵͳ £¬ÖØÒª½â¾öÊý¾ÝÑз¢ETLÅ̸ù´í½ÚµÄÒÀÀµ¹ØÏµ £¬¶ø²»ÄÜÖ±¹Û¼à¿Ø¹¤×÷½¡È«×´Ì¬µÈÎÊÌâ¡£

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Horde_Groupware_Webmail_Edition_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶[ZDI-20-1051]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

HordeGroupwareWebmailÊÇÃÀ¹úHorde¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷µÄÆóÒµ¼¶Í¨Ñ¶Ì×¼þ¡£HordeGroupwareWebmailÖдæÔÚ´úÂë×¢Èë·ì϶¡£ÔÊÐí¹¥»÷ÕßÔÚIMP_Prefs_SortÀàµÄ»ú¹Øº¯ÊýÖжԲ»ÊÜÐÅÀµµÄÊý¾Ý·ì϶½øÐз´ÐòÁл¯¡£µÍÌØÈ¨µÄ¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µãÀ´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

¸üй¦·ò£º

20220708


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_MidaSolutionseFramework_ajaxreq.phpºÅÁî×¢Èë·ì϶[CVE-2020-15920][CNNVD-202007-1517]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

MidaSolutionsÊÇÒ»¼ÒרһÓÚͳһͨѶ(UC)µÄ¸ß¼¼ÊõÒâ´óÀû¹«Ë¾,MidaÍŶÓÒѳÉΪͳһºÏ×÷ºÍרҵ¹µÍ¨µÄÈ«Çò¸¨µ¼Õß,ÏÕЩËùÓÐÐÐÒµµÄ·þÎñÌṩÉÌ £¬ÏµÍ³¼¯³ÉÉÌ¡£ÆäºÏ×÷ͬ°éÓÐ΢Èí,˼¿Æ,»ÝÆÕ,ÖйúµçÐŵÈ40¸öÊÀ½ç³ÛÃûÆóÒµ¡£MidaeFrameworkÊÇMidaSolutions¹«Ë¾ÆìÏÂÊÓÆµºÍÓïÒôÀûÓ÷¨Ê½µÄÆëÈ«·þÎñÌ×¼þ £¬ÓëÏÕЩËùÓÐÖØÒªµÄUCƽ̨¼æÈÝ¡£¸ÃÌ×¼þÔ̺¬»°ÎñÔ±½ÚÔį̀ £¬¼Í¼Æ÷ £¬´«Õæ·þÎñÆ÷ £¬¼Æ·Ñ £¬¶ÓÁÐÖÎÀíÆ÷ £¬×Ô¶¯»°ÎñÔ± £¬Òƶ¯ÀûÓ÷¨Ê½ £¬µç»°·þÎñ¡£MidaSolutionseFramework2.9.0¼°Ö®Ç°°æ±¾ÖдæÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£Ëüʹδ¾­Éí·ÝÈÏÖ¤µÄ¹¥»÷Õß¿ÉÄÜ»ñµÃÓµÓÐÖÎÀí£¨root£©ÌØÈ¨µÄÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£×¢ÈëµãλÓÚδ¹«¿ªµÄPHPÒ³ÃæÉÏ £¬¸ÃÒ³ÃæÄܹ»Ê¹ÓÃGET»òPOST¶ñÒâ¸ºÔØ×÷Ϊָ±ê¡£

¸üй¦·ò£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_SaltStack_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-16846/CVE-2020-25592][CNNVD-202011-302/CNNVD-202011-308]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÔÚÀûÓÃSaltStackµÄsalt-api½Ó¿ÚÖ´ÐÐËÁÒâºÅÁSaltStackÊÇÒ»¸öÉ¢²¼Ê½ÔËάϵͳ £¬ÔÚ»¥ÁªÍø³¡¾°Öб»¿í·ºÀûÓà £¬ÓÐÒÔÏÂÁ½¸öÖØÒªÖ°ÄÜ£ºÅäÖÃÖÎÀíϵͳ £¬¿ÉÄܽ«Ô¶³Ì½ÚµãÊØ»¤ÔÚÒ»¸öÔ¤Ô¼ÒåµÄ״̬£¨ÀýÈç £¬È·±£×°ÖÃÌØ¶¨µÄÈí¼þ°ü²¢ÔËÐÐÌØ¶¨µÄ·þÎñ£©É¢²¼Ê½Ô¶³ÌÖ´ÐÐϵͳ £¬ÓÃÓÚÔÚÔ¶³Ì½ÚµãÉϵ¥¶À»òͨ¹ýËÁÒâÑ¡Ôñ³ß¶ÈÀ´Ö´ÐкÅÁîºÍ²éÎÊÊý¾Ý¡£¸ÃÊÂÎñÓÉÁ½¸ö×éºÏµÄCVE·ì϶µÄʹÓòúÉú £¬Í¨¹ýCVE-2020-25592»ú¹ØËÁÒâ¡°eauth¡±/¡°token¡±Öµ £¬ÈƹýÉí·ÝÈÏÖ¤£»Í¨¹ýCVE-2020-16846Ö´ÐÐshell¡£

¸üй¦·ò£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_SQL_Server_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-0618][CNNVD-202002-496]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS) £¬ÊÇ´Ë¿ÌÊÀ½çÉÏ¿í·ºÊ¹ÓõÄÊý¾Ý¿âÖ®Ò»¡£¸Ã·ì϶ԴÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesÊ·ý·¢Ë;«ÐÄ»ú¹ØµÄÒªÇó £¬¿ÉÀûÓô˷ì϶ÔÚ±¨±í·þÎñÆ÷·þÎñÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220708

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_PHP·´ÐòÁл¯¶ÔÏóÌåʽÊý¾Ý·¢ÏÖ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö:

Èô·¨Ê½Î´¶ÔÓû§ÊäÈëµÄÐòÁл¯×Ö·û´®½øÐмì²â £¬Ôò¿ÉÄܵ¼Ö¹¥»÷ÕßÄܹ»½ÚÔì·´ÐòÁл¯¹ý³Ì £¬Í¨¹ýÔÚ²ÎÊýÖÐ×¢ÈëһЩ´úÂë £¬´Ó¶ø´ïµ½´úÂëÖ´ÐÐ £¬SQL×¢Èë £¬Ä¿Â¼±éÀúµÈ²»³É¿Øºó¹û¡£

¸üй¦·ò£º

20220708