ÿÖÜÉý¼¶Í¨¸æ-2022-05-03
Ðû²¼Ê±¼ä 2022-05-03ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_VMware-Workspace-ONE-Access_Ä£°å×¢Èë_ÃüÁîÖ´ÐÐ[CVE-2022-22954][CNNVD-202204-2551] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | VMwareWorkspaceONEAccess£¨ÒÔÇ°³ÆΪVMwareIdentityManager£©Ö¼ÔÚͨ¹ý¶àÒòËØÉí·ÝÑéÖ¤¡¢Ìõ¼þ·ÃÎʺ͵¥µãµÇ¼£¬ÈÃÄúµÄÔ±¹¤¸ü¿ìµØ·ÃÎÊSaaS¡¢WebºÍ±¾»úÒƶ¯Ó¦Ó÷¨Ê½¡£CVE-2022-22954ÊÇÒ»¸öÄäÃû·þÎñÆ÷Ä£°å×¢È멶´£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓôË©¶´½øÐÐÔ¶³ÌÈÎÒâ´úÂëÖ´ÐС£ÊÜÓ°Ïì°æ±¾ÈçÏ£ºVMwareWorkspaceONEAccessAppliance£¨°æ±¾ºÅ£º20.10.0.0£¬20.10.0.1£¬21.08.0.0£¬21.08.0.1£©VMwareIdentityManagerAppliance£¨°æ±¾ºÅ£º3.3.3£¬3.3.4£¬3.3.5£¬3.3.6£©VMwareRealizeAutomation£¨°æ±¾ºÅ£º7.6£© |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_WSO2-fileupload_ÈÎÒâÎļþÉÏ´«[CVE-2022-29464][CNNVD-202204-3737] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | WSO2-APIManagerÊÇÃÀ¹úWSO2¹«Ë¾µÄÒ»Ì×APIÉúÃüÖÜÆÚ¹ÜÀí½â¾ö·½°¸¡£WSO2-APIManager´æÔÚÄþ¾²Â©¶´£¬¸Ã©¶´ÔÊÐíÎÞÏÞÖƵÄÎļþÉÏ´«´Ó¶øÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_Webshell_AntswordľÂí_ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | Á÷Á¿Öмì²âµ½AntswordµÄ¿ØÖÆÃüÁ¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ½øÐÐÁ¬½ÓÐÐΪ¡£¸ÃWebshellÖ÷Ҫͨ¹ýJavaÖÐJSÒýÇæʵÏÖµÄÒ»¾ä»°Ä¾Âí£¬¸ÄÉÆÁË´«Í³½á¹¹×Ö½ÚÂ뷽ʽÌØÕ÷Ã÷ÏÔ£¬payloadÈÝÁ¿´óµÈȱµã¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ÒÚÓʵç×ÓÓʼþϵͳ_Ô¶³ÌÃüÁîÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃÒÚÓʵç×ÓÓʼþϵͳͨ¹ýÐÞ¸ÄcookieÔÚÄ¿µÄipÖ÷»úÖ´ÐÐÔ¶³Ì´úÂëÖ´ÐвÙ×÷£¬ÒÚÓʵç×ÓÓʼþϵͳÊÇÓɱ±¾©ÒÚÖÐÓÊÐÅÏ¢¼¼ÊõÓÐÏÞ¹«Ë¾£¨ÒÔϼò³ÆÒÚÓʹ«Ë¾£©¿ª·¢µÄÒ»¿îÃæÏòÖдóÐͼ¯ÍÅÆóÒµ¡¢Õþ¸®¡¢¸ßУÓû§µÄ¹ú²úÓʼþϵͳ¡£ÒÚÓʵç×ÓÓʼþϵͳ½ÓÄÉÁË×ÔÖ÷Ñз¢MTAÒýÇæ¡¢ÂþÑÜʽÎļþϵͳ´æ´¢·½Ê½¡¢¶à¶ÔÁлúÖÆ¡¢ECS´æ´¢×Óϵͳ¡¢CacheϵͳµÈ¶àÏîºËÐļ¼Êõ£¬ÌṩÁ˸»ºñµÄÓʼþ¹¦Ð§¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_TamronOS-IPTVϵͳ_ÈÎÒâÃüÁîÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | TamronOSIPTV/VODϵͳÊÇÒ»Ì×»ùÓÚLinuxÄں˿ª·¢µÄ¿í´øÔËÓªÉÌ¡¢¾Æµê¡¢Ñ§Ð£Ö±²¥µã²¥Ò»Ìå½â¾ö·½°¸¡£TamronOSIPTVϵͳapi/ping´æÔÚÈÎÒâÃüÁîÖ´ÐЩ¶´£¬¹¥»÷Õßͨ¹ý©¶´¿ÉÒÔÖ´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | TCP_½©Ê¬ÍøÂç_BillGates_¿ØÖÆÃüÁî |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½BillGatesµÄC&C·þÎñÆ÷ÊÔͼ·¢ËÍ¿ØÖÆÃüÁî¸øBillGates£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçBillGates¡£BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂ磬Ö÷Òª¹¦Ð§ÊÇÕë¶ÔÖ¸¶¨Ä¿±ê½øÐÐDDoS¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_PhpTax_pfilez²ÎÊý_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | PhpTax0.8°æ±¾ÖдæÔÚÒ»¸öÔ¶³Ì´úÂë×¢È멶´£¬¸Ã©¶´Ô´ÓÚÔÚÉú³ÉPDFʱ£¬drawimage.phpÖеÄicondrawpng()º¯ÊýÎÞ·¨ÕýÈ·´¦ÖÃpfilez²ÎÊý£¬¸Ã²ÎÊý½«ÔÚexec()Óï¾äÖÐʹÓ᣹¥»÷Õß¿ÉÒÔͨ¹ýÔÚpfilez²ÎÊý×¢Èë¶ñÒâÄÚÈÝʵÏÖÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_´úÂëÖ´ÐÐ_MobileIron_MDM_·´ÐòÁл¯Â©¶´[CVE-2020-15505][CNNVD-202007-291] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃMobileIron_MDMµÄ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´µÄ³ÉÒòÊÇMobileIron_MDMʹÓÃÁËHessianÐÒéµÄJavaÖеÄÈÎÒâ·´ÐòÁл¯¡£MobileIronÊÇÈ«ÇòÁìÏÈÇÒÉú³¤×îѸËÙµÄÒƶ¯IT½â¾ö·½°¸³§ÉÌÖ®Ò»£¬ÔÚÈ«ÇòÓнü20000¼Ò¹«Ë¾Ê¹ÓÃMobileIronµÄÒƶ¯É豸¹ÜÀí½â¾ö·½°¸£¨MDM£©¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_´úÂëÖ´ÐÐ_PHPCMS_v2008_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2018-19127][CNNVD-201811-248] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃPHPCMS_v2008ÈÎÒâ´úÂëÖ´ÐЩ¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬¸Ã©¶´ÀûÓÃtype.phpÎļþ½á¹¹¶ñÒ⻺´æÎļþ£¬·ÃÎʸûº´æÎļþ¿ÉÒÔ»ñÈ¡Óû§È¨ÏÞ¡£PHPCMSÊÇ¿ªÔ´µÄÕûվϵͳ¡£PHPCMS´æÔÚPHPCMS_v2008ÈÎÒâ´úÂëÖ´ÐЩ¶´£¬¹¥»÷ÕßÀûÓôË©¶´ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡Êý¾Ý¿âºÍ¹ÜÀíԱȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Netlink_GPON·ÓÉÆ÷ÃüÁî×¢È멶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Netlink-GPON·ÓÉÆ÷µÄWeb·þÎñ´æÔÚÃüÁî×¢È멶´£¬¹¥»÷Õß¿Éͨ¹ýÏòÇëÇóÌåÖеÄÌض¨Î»ÖòåÈë¶ñÒâÔغɣ¬Ö´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_ͨ´ïOA_ÈÎÒâÎļþÉÏ´«/Îļþ°üÂÞ©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ͨ´ïOAÊÇÒ»Ìװ칫ϵͳ¡£ÓÉÓÚͨ´ïOAÖдæÔÚµÄÁ½Ã¶Â©¶´(ÎļþÉÏ´«Â©¶´£¬Îļþ°üÂÞ©¶´)£¬¹¥»÷Õß¿Éͨ¹ýÕâÁ½Ã¶Â©¶´ÊµÏÖÔ¶³ÌÃüÁîÖ´ÐС£/ispirit/im/upload.php´æÔÚÈƹýµÇ¼(ÈÎÒâÎļþÉÏ´«Â©¶´)£¬½áºÏgateway.php´¦´æÔÚµÄÎļþ°üÂÞ©¶´£¬×îÖÕµ¼ÖÂgetshell¡£ |
¸üÐÂʱ¼ä£º | 20220503 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ExifTool_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2021-22204] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ExifToolÊÇÒ»¸ö¶ÀÁ¢ÓÚƽ̨µÄPerl¿â£¬Ò²ÓÐÒ»¸öÃüÁîÐÐÓ¦Ó÷¨Ê½£¬ÓÃÓÚ¶ÁÈ¡£¬Ð´ÈëºÍ±à¼ÖÖÖÖÎļþÖеÄÔªÐÅÏ¢¡£¸Ã©¶´ÊÇÓÉÓÚExifTool°æ±¾7.44°æ±¾ÖдæÔÚ¶ÔDjVuÎļþ¸ñʽµÄÊý¾Ý´¦Öò»Íס£¹¥»÷Õß¿ÉÀûÓø鶴ÔÚº¬ÓЩ¶´°æ±¾µÄExifTool¿âµÄÓ¦Ó÷þÎñÆ÷»òÕßÓ¦Ó÷¨Ê½Ï£¬½á¹¹¶ñÒâDjVuÎļþ£¬·þÎñÆ÷»òÕßÓ¦Ó÷¨Ê½Ô¶³Ìµ±µØ½âÎö´ËÎļþ£¬µ¼ÖÂÈÎÒâ´úÂëÖ´ÐУ¬×îÖÕ»ñÈ¡·þÎñÆ÷×î¸ßȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220503 |