ÿÖÜÉý¼¶Í¨¸æ-2022-01-04

Ðû²¼Ê±¼ä 2022-01-04

ÐÂÔöʼþ



ʼþÃû³Æ£º

HTTP_ntopng_ȨÏÞÈƹý©¶´[¹¥»÷ʵÑé][CVE-2021-28073]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

ntopngÊÇÒ»¿î»ùÓÚWebµÄÁ÷Á¿·ÖÎöÓ뼯Á÷¹¤¾ß¡£ntopng´æÔÚȨÏÞÈƹý©¶´£¬ÆäCVEºÅΪCVE-2021-28073¡£¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇó£¬ÈƹýÏà¹ØÈÏÖ¤£¬ÅäºÏÏà¹Ø¹¦Ð§Ôì³ÉÈÎÒâ´úÂëÖ´ÐУ¬¿ØÖÆ·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PbootCMS_v2.0.7_ǰ̨Îļþ°üÂÞ©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

PbootCMSÊÇÒ»¿î¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾¿ª·¢½¨Éè¹ÜÀíϵͳ¡£pbootcms2.07°æ±¾ÖÐǰ̨¿ØÖÆÆ÷TagControllerÖеÄindexÒªÁì´æÔÚÎļþ°üÂÞ©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´»ñÈ¡Ä¿±êÖ÷»úȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PbootCMS_v2.0.7_ÈÎÒâÎļþ¶ÁÈ¡

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

PbootCMSÊÇÒ»¿î¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾¿ª·¢½¨Éè¹ÜÀíϵͳ¡£pbootcms2.07°æ±¾ÖÐǰ̨list²ÎÊý´æÔÚÈÎÒâÎļþ¶Áȡ©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´»ñÈ¡Ä¿±êÖ÷»úȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_DedeCMSV6.0.3_catalog_edit.php_Ô¶³Ì´úÂëÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢£¬¾ßÓкÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬¶øÇÒÍêÈ«¿ª·ÅÔ´´úÂë¡£Æäºǫ́catalog_edit.phpÎļþ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÀûÓôË©¶´Äõ½Ä¿±êÖ÷»úȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_DedeCMSV6.0.3_freelist_edit.php_Ô¶³Ì´úÂëÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢£¬¾ßÓкÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬¶øÇÒÍêÈ«¿ª·ÅÔ´´úÂë¡£Æäºǫ́freelist_edit.phpÎļþ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÀûÓôË©¶´Äõ½Ä¿±êÖ÷»úȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

TCP_Éó¼Æʼþ_JAVA_LDAPÇëÇóµ÷ÓÃ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄÖ÷»ú½øÐÐLDAPÇëÇó¡£LDAPÊÇÒ»¸öÇáÁ¿¼¶Ä¿Â¼·ÃÎÊЭÒé¡£ÈôÔ´IPÖ÷»ú´æÔÚJAVA·´ÐòÁл¯Â©¶´£¬¹¥»÷Õß¿ÉÀûÓÃJNDIÀ´µ÷ÓÃLDAP£¬¿ÉÄÜ´æÔÚÔ¶³Ì·ÃÎʶñÒ⹤¾ßµÄ·çÏÕ¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

TCP_Éó¼Æʼþ_JAVA_RMIÇëÇóµ÷ÓÃ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄÖ÷»ú½øÐÐRMIÇëÇó¡£RMI¼´Ô¶³ÌÒªÁìµ÷ÓÃ(RemoteMethodInvocation)£¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³Ì¹ý³Ìµ÷ÓõÄJavaAPI¡£ÈôÔ´IPÖ÷»ú´æÔÚJAVA·´ÐòÁл¯Â©¶´£¬¹¥»÷Õß¿ÉÀûÓÃJNDIÀ´µ÷ÓÃRMI£¬¿ÉÄÜ´æÔÚÔ¶³Ì·ÃÎʶñÒ⹤¾ßµÄ·çÏÕ¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Ô¶³Ì·ÃÎÊJava_classÎļþ

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö:

´Ëʼþ¼ì²âJAVAÔ¶³Ì·ÃÎÊclassÎļþµÄÐÐΪ¡£ÔÚjava©¶´ÖУ¬´æÔÚ´óÁ¿·´ÐòÁл¯ºÍÃüÁîÖ´ÐЩ¶´»áʹÓõ½Ô¶³Ìµ÷ÓÃЭÒéÈ¥·ÃÎʶñÒâÀàµÄÊÖ·¨£¬À´ÊµÏÖÈÎÒâÃüÁîÖ´ÐУ¬Î£º¦½Ï´ó¡£

¸üÐÂʱ¼ä£º

20220104

 

ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_JAVA_µ÷ÓÃRMIÔ¶³ÌÏÂÔØclass

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

´Ëʼþ¼ì²âJAVAµ÷ÓÃRMIÔ¶³ÌÏÂÔØclassµÄÐÐΪ¡£RMI¼´Ô¶³ÌÒªÁìµ÷Óã¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³Ì¹ý³Ìµ÷ÓõÄjavaAPI.ÔÚjava©¶´ÖУ¬´æÔÚ´óÁ¿·´ÐòÁл¯ºÍÃüÁîÖ´ÐЩ¶´»áʹÓõ½RMIÔ¶³Ì·ÃÎʶñÒâÀàµÄÊÖ·¨£¬À´ÊµÏÖÈÎÒâÃüÁîÖ´ÐУ¬Î£º¦½Ï´ó¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_Pupy_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö:

¼ì²âµ½Óɺڿ͹¤¾ßPupyÉú³ÉµÄhttpÔ¶¿ØºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£Ö´Ðк󣬹¥»÷Õß¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¶à¹¦Ð§Ô¶¿ØºóÃźͺóÉø͸¹¤¾ß¡£Ëü¾ßÓÐall-in-memoryÖ´Ðй¦Ð§£¬Õ¼Óÿռä·Ç³£Ð¡¡£Pupy¿ÉÒÔʹÓöàÖÖ·½Ê½½øÐÐͨÐÅ£¬Ê¹Ó÷´Éä×¢ÈëǨÒƵ½½ø³ÌÖУ¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢python°üºÍpythonC-extensions¡£

¸üÐÂʱ¼ä£º

20220104


ʼþÃû³Æ£º

UDP_ľÂíºóÃÅ_Pupy_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö:

¼ì²âµ½Óɺڿ͹¤¾ßPupyÉú³ÉµÄhttpÔ¶¿ØºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£Ö´Ðк󣬹¥»÷Õß¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¶à¹¦Ð§Ô¶¿ØºóÃźͺóÉø͸¹¤¾ß¡£Ëü¾ßÓÐall-in-memoryÖ´Ðй¦Ð§£¬Õ¼Óÿռä·Ç³£Ð¡¡£Pupy¿ÉÒÔʹÓöàÖÖ·½Ê½½øÐÐͨÐÅ£¬Ê¹Ó÷´Éä×¢ÈëǨÒƵ½½ø³ÌÖУ¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢python°üºÍpythonC-extensions¡£

¸üÐÂʱ¼ä£º

20220104

 

ÐÞ¸Äʼþ


 

ʼþÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Â©¶´[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú½øÐÐĿ¼´©Ô½Â©¶´¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Â©¶´ÄÜʹ¹¥»÷ÕßÈƹýWeb·þÎñÆ÷µÄ·ÃÎÊÏÞÖÆ£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ÈÎÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬ÆäËû©¶´£¨ÉõÖÁһЩ0day©¶´£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´Ëʼþ±¨¾¯¡£ÓÉÓÚÕý³£ÒµÎñÖÐÒ»°ã²»»á·¢Éú´ËʼþÌØÕ÷µÄÁ÷Á¿£¬ËùÒÔÐèÒªÖصã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÃÎÊÃô¸ÐÎļþ¡£

¸üÐÂʱ¼ä£º

20220104

 

ʼþÃû³Æ£º

HTTP_ÅÀ³æBot·ÃÎÊ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö:

¼ì²âµ½ÅÀ³æBot¶ÔÄ¿µÄIPÖ÷»úµÄweb·ÃÎÊ,¿ÉÄÜÔÚ¶ÔÄ¿µÄIPÖ÷»ú½øÐÐÒ³ÃæÅÀÈ¡¡£

¸üÐÂʱ¼ä£º

20220104