ÿÖÜÉý¼¶²¼¸æ-2023-02-28

°ä²¼¹¦·ò 2023-02-28

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ºÅÁîÖ´ÐÐ_GLPI_htmLawedTest.php

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃGLPIÖÐhtmLawedTest.php´¦µÄ·ì϶   £¬½øÐÐÔ¶³ÌËÁÒâºÅÁîÖ´ÐС£GLPIÊÇÓ×ÎÒ¿ª·¢ÕßµÄÒ»¿î¿ªÔ´ITºÍ×ʲúÖÎÀíÈí¼þ¡£¸ÃÈí¼þÌṩְÄÜÈ«ÃæµÄIT×ÊÔ´ÖÎÀí½Ó¿Ú   £¬ÄãÄܹ»ÓÃËüÀ´³ÉÁ¢Êý¾Ý¿âÈ«ÃæÖÎÀíITµÄµçÄÔ   £¬ÏÔʾÆ÷   £¬·þÎñÆ÷   £¬´òÓ¡»ú   £¬ÍøÂçÉ豸   £¬µç»°   £¬ÉõÖÁÎø¹ÄºÍÄ«ºÐµÈ¡£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_δÊÚȨ½Ó¼û_Apache_AXIS_AdminService

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃApacheAxisδÊÚȨ½Ó¼û·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£ApacheAxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷   £¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API   £¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓ᣷ì϶ÐÔÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÅäÖÃÃýÎó¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ   £¬¹¥»÷ÕßÄܹ»»ú¹ØWebServiceŲÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀà   £¬Ô¶³ÌÀûÓÃAdminService½Ó¿Ú½øÐÐWebService°ä²¼   £¬ÔٴνӼûÌìÉúµÄWebService½Ó¿Ú   £¬´«ÈëÒªÖ´ÐеĺÅÁî   £¬¾ÍÄܹ»½øÐÐÔ¶³ÌºÅÁîÖ´Ðзì϶µÄÀûÓá£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_IBM_Aspera_Faspex[CVE-2022-47986]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

IBMAsperaFaspexÊÇÒ»¸ö»ùÓÚIBMAspera¸ß¿ì´«Êä·þÎñÆ÷¹¹½¨µÄÎļþ»¥»»ÀûÓ÷¨Ê½   £¬×÷Ϊ¼¯Öд«Êä½â¾ö¹æ»®¡£½èÖú»ùÓÚWebµÄGUI   £¬FaspexΪFASP¸ß¿ì´«ÊäÌṩÁ˸߼¶ÖÎÀíÑ¡Ïî   £¬ÒÔÆ¥ÅäÓйصŤ×÷Á÷³Ì¡£ÓÉÓÚYAML·´ÐòÁл¯È±µã   £¬IBMAsperaFaspexÄܹ»ÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂ롣ͨ¹ý·¢Ëͳö¸ñÔì×÷µÄ¹ýÆÚAPIŲÓà   £¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£Ó°Ïì°æ±¾£ºFaspex<=4.4.2

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_logging.config

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃActuatorµÄ/evn½Ó¿Úͨ¹ýlogging.config²ÎÊý³¢ÊÔÔ¶³Ì´úÂëÖ´ÐС£SpringBootActuatorÊÇÒ»¿îÄܹ»Ô®ÊÖÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,ÆäÄܹ»¼à¿ØºÃ¶àºÃ¶àµÄϵͳÊý¾Ý,ËüÓжÔÀûÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯³É¹¦ÄÜ   £¬Äܹ»²é¿´ÀûÓÃÅäÖõľßÌåÐÅÏ¢¡£

¸üй¦·ò£º

20230228

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Discuz_X_uc_center

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Discuz!MLϵͳÖÐ   £¬Í¨¹ýºó¶ÜÅú¸ÄUcenterÊý¾Ý¿âÏνÓÐÅÏ¢   £¬¿É½«¶ñÒâ´úÂëдÈëconfig/config_ucenter.phpÎļþÖÐ   £¬µ¼Ö´úÂëÖ´ÐС£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Discuz!X3.4

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Discuz!MLϵͳװÖúóδµÇ½ºó¶Üʱ   £¬¿ÉÀûÓÃÎļþɾ³ý·ì϶ɾµôinstall.lockÎļþ   £¬Èƹý¶Ô×°ÖÃʵÏÖµÄÅжϿÉÄÜÔÙ½øÐÐ×°ÖõĹý³Ì   £¬¶øºó½«¶ñÒâ´úÂëдÈëÅäÖÃÎļþÖдӶøÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_Phpcms:V9.5.8_ºó¶ÜÖÎÀí

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCMS-Phpcms:V9.5.8ºó¶ÜËÁÒâ´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ   £¬¸Ã·ì϶ÀûÓÃcontent.phpÎļþ»ú¹Ø¶ñÒâpayload   £¬´Ó¶øÔì³É´úÂëÖ´ÐС£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_SpamTitanÍø¹Ø[CVE-2020-11699][CNNVD-202009-1082]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

SpamTitanÍø¹ØÊÇÖ°ÄÜ׳´óµÄ·´À¬»øÓʼþÉ豸   £¬ËüÎªÍøÂçÖÎÀíÔ±ÌṩÁË¿í·ºµÄ¹¤¾ßÀ´½ÚÔìÓʼþÁ÷²¢Ô¤·ÀÓк¦µÄµç×ÓÓʼþºÍ¶ñÒâÈí¼þ¡£ÓÉÓÚ´æÔÚ´úÂëȱµã   £¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâpayload   £¬Ê¹µÃÖ¸±êÖ÷»úÖ´ÐжñÒâºÅÁî¡£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_¿úËÅɨÃè_ɨÃèÆ÷_DisBuster

°²È«ÀàÐÍ£º

°²È«É¨Ãè

ÊÂÎñÃèÊö£º

DisBusterÊÇÉøÈë²âÊÔ¹ý³ÌÖг£ÓõÄɨÃ蹤¾ß   £¬Äܹ»×Ô½ç˵¼ÓÔØ×Ô½ç˵×Öµä¶ÔÖ¸±ê½øÐÐĿ¼»òÒ³ÃæÉ¨ÃèºÍ±¬ÆÆ¡£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Weblogic_ForeignOpaqueReference×é¼þ_JNDI×¢Èë_´úÂëÖ´ÐÐ[CVE-2023-21839]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨   £¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½   £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£ÓÉÓÚForeignOpaqueReferenceÀà´æÔÚ°²È«ÎÊÌâ   £¬CVE-2023-21839·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3/IIOPºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷   £¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°ÏìÁìÓò£ºOracleWebLogicServer12.2.1.3.0OracleWebLogicServer12.2.1.4.0OracleWebLogicServer14.1.1.0.0

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Apache_Log4j2_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-44228][CNNVD-202112-799]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ApacheLog4j2ÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â   £¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£ÔÚApacheLog4j22.15.0_rc1֮ǰµÄ2.x°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶Զ³ÌÖ´ÐÐËÁÒâ´úÂë

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_SQL×¢Èë_Django_kind_lookup_name[CVE-2022-34265][CNNVD-202207-347]

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

DjangoÊÇÒ»¸ö»ùÓÚPythonµÄ¿ªÔ´WebÀûÓÿò¼Ü¡£Django´æÔÚÒ»¸öSQL×¢Èë·ì϶£¨CVE-2022-34265£©¡£ÔÚÊÜÓ°ÏìµÄDjango°æ±¾£¨3.2.14¡¢4.0.6֮ǰµÄ°æ±¾£©ÖÐ   £¬Äܹ»Í¨¹ý´«µÝ¶ñÒâÊý¾Ý×÷Ϊkind/lookup_nameµÄÖµ   £¬ÈôÊÇÀûÓ÷¨Ê½ÔÚ½«ÕâЩ²ÎÊý´«µÝ¸øTrunc()ºÍExtract()Êý¾Ý¿âº¯Êý£¨ÈÕÆÚº¯Êý£©Ö®Ç°Ã»Óо­¹ýÊäÈë¹ýÂË»òתÒå   £¬ÔòÈÝÒ×Êܵ½SQL×¢Èë¹¥»÷¡£Í¨¹ýÀûÓô˷ì϶   £¬µÚÈý·½Äܹ»ÏòÊý¾Ý¿â·¢ËͺÅÁîÒÔ½Ó¼ûδ¾­ÊÚȨµÄÊý¾Ý»òɾ³ýÊý¾Ý¿âµÈ¶ñÒâÐÐΪ¡£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

TCP_·ì϶ÀûÓÃ_·´ÐòÁл¯_Weblogic_T3ºÍ̸[CVE-2020-14756][CVE-2020-14756/CVE-2021-2394]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨   £¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½   £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£CVE-2020-2555·ì϶Äܹ»ÈƹýºÚÃûµ¥Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»°²È«µÄextract²½Öè   £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷   £¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°ÏìÁìÓò£ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_jolokia_logback_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃActuatorµÄ/jolokia½Ó¿ÚŲÓÃch.qos.logback.classic.jmx.JMXConfiguratorÀàµÄreloadByURL²½ÖèÉèÖÃ±í²¿ÈÕÖ¾ÅäÖÃurlµØÖ·¡£SpringBootActuatorÊÇÒ»¿îÄܹ»Ô®ÊÖÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,ÆäÄܹ»¼à¿ØºÃ¶àºÃ¶àµÄϵͳÊý¾Ý,ËüÓжÔÀûÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯³É¹¦ÄÜ   £¬Äܹ»²é¿´ÀûÓÃÅäÖõľßÌåÐÅÏ¢¡£JolokiaÔÊÐíͨ¹ýHTTP½Ó¼ûËùÓÐÒÑ×¢²áµÄMBean   £¬Í¬Ê±Äܹ»Ê¹ÓÃURLÁгöËùÓпÉÓõÄMBeans²Ù×÷¡£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÒªÇó

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂí³¢ÊÔÏνӿó³Ø   £¬Êܺ¦Ö÷»ú±äÂý¡£

¸üй¦·ò£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_WebLogic_·´ÐòÁл¯·ì϶[CVE-2018-3252][CNNVD-201810-843]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃWeblogic»ú¹Ø¶ñÒâ·´ÐòÁдúÂëÖ´ÐÐËÁÒâºÅÁî £»OracleWeblogicServerÊÇÀûÓ÷¨Ê½·þÎñÆ÷¡£WeblogicÀûÓ÷þÎñÆ÷µÄApacheConnectorÄ£¿éÖеÄmod_wlδ¶ÔÓû§Ìá½»µÄÊäÈëÊý¾Ý½øÐÐÕýÈ·²é³­   £¬Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶½øÐлº³åÇøÒç³ö¹¥»÷   £¬¿Éµ¼Ö»ؾø·þÎñ»òËÁÒâ´úÂëÖ´Ðй¥»÷¡£¹¥»÷ÕßÄܹ»Ìá½»Ô̺¬³¬³¤Êý¾ÝµÄPOSTÒªÇó´¥·¢´Ë·ì϶   £¬¾«ÐĹ¹½¨Ìá½»Êý¾Ý¿Éµ¼ÖÂÒÔÀûÓ÷¨Ê½È¨ÏÞÖ´ÐÐËÁÒâÖ¸Áî   £¬»ñµÃ·þÎñÆ÷µÄ½ÚÔìȨ¡£

¸üй¦·ò£º

20230228