ÿÖÜÉý¼¶Í¨¸æ-2022-10-18

Ðû²¼Ê±¼ä 2022-10-18
ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_webuploader_0.1.15_ÎļþÉÏ´«

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃwebuploader0.1.15°æ±¾ÖдæÔÚµÄÎļþÉÏ´«Â©¶´½øÐй¥»÷ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£WebUploaderÊÇÓÉBaiduWebFE(FEX)ÍŶӿª·¢µÄÒ»¸ö¼òµ¥µÄÒÔHTML5ΪÖ÷ £¬FLASHΪ¸¨µÄÏÖ´úÎļþÉÏ´«×é¼þ¡£ÔÚÏÖ´úµÄä¯ÀÀÆ÷ÀïÃæÄܳäʵ·¢»ÓHTML5µÄÓÅÊÆ £¬Í¬Ê±ÓÖ²»ÞðÆúÖ÷Á÷IEä¯ÀÀÆ÷ £¬ÑØÓÃÔ­À´µÄFLASHÔËÐÐʱ £¬¼æÈÝIE6+ £¬iOS6+,android4+¡£Á½Ì×ÔËÐÐʱ £¬Í¬ÑùµÄµ÷Ó÷½Ê½ £¬¿É¹©Óû§ÈÎÒâÑ¡Óá£

¸üÐÂʱ¼ä£º

20221018

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2963]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯Â©¶´ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PHP-zerodiumºóÃÅ_ÈÎÒâ´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄ·ÖÎö¹ý³ÌÖз¢ÏÖ £¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»½Ù³ÖµÄÍøÕ¾ÉÏ £¬¶øÇÒ½ÓÄÉÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷ £¬¶øÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢ÈËÔ±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£Ä¿Ç°ÎªÖ¹PHP¹Ù·½²¢Î´¾Í¸Ãʼþ½øÐиü¶àÅû¶ £¬ÌåÏִ˴ηþÎñÆ÷±»ºÚµÄ¾ßÌåϸ½ÚÈÔÔÚÊӲ쵱ÖС£ÓÉÓÚ´ËʼþµÄÓ°Ïì £¬PHPµÄ¹Ù·½´úÂë¿âÒѾ­±»Î¬»¤ÈËԱǨÒÆÖÁGitHubƽ̨ £¬Ö®ºóµÄÏà¹Ø´úÂë¸üС¢Ð޸Ľ«»á¶¼ÔÚGitHubÉϽøÐС£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_WebLogic_·´ÐòÁл¯_XXE×¢Èë[CVE-2020-2949]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃweblogic3.7.1.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾´æÔڵķ´ÐòÁл¯Â©¶´ £¬Í¨¹ýt3ЭÒéͨ±¨¶ñÒâµÄÐòÁл¯Êý¾Ý´Ó¶ø´¥·¢XXE©¶´ £¬¶ÁÈ¡Ä¿±êϵͳÃô¸ÐÎļþ¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14825]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃ10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0ºÍ14.1.1.0.0°æ±¾µÄweblogicÖдæÔڵķ´ÐòÁл¯Â©¶´ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_×¢Èë¹¥»÷_apache_solr_XXE×¢Èë[CVE-2018-1308][CNNVD-201804-415]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÀûÓÃApachesolr1.2-6.6.2ºÍ7.0.0-7.2.1°æ±¾ÖдæÔÚµÄXXE©¶´½øÐÐÎļþ¶ÁÈ¡²Ù×÷ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳµÄÃô¸ÐÐÅÏ¢¡£ApacheSolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷·þÎñ £¬Ê¹ÓÃJavaÓïÑÔ¿ª·¢ £¬Ö÷Òª»ùÓÚHTTPºÍApacheLuceneʵÏֵġ£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-24616][CNNVD-202008-1195]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃFasterXMLJacksonµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´ÏòÄ¿µÄip½øÐз´ÐòÁл¯¹¥»÷¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_dbcp2_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36180/CVE-2020-36182/CVE-2020-36184/CVE-2020-36185][CNNVD-202101-326/CNNVD-202101-325/CNNVD-202101-344/CNNVD-202101-337]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃFasterXMLjackson-databind<2.9.9.2ºÍ>=2.0.0,<=2.9.10.7°æ±¾ÖдæÔڵķ´ÐòÁл¯Â©¶´ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´® £¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_IBM_WebSphere_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-4279]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼÀûÓÃIBM_WebSphereV9.0.0.0-V9.0.0.11 £¬V8.5.0.0-V8.5.5.15 £¬v7.0ÖдæÔڵĴúÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2555]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÀûÓÃweblogic·´ÐòÁл¯Â©¶´½øÐй¥»÷µÄÐÐΪ £¬OracleCoherenceΪOracleÈÚºÏÖмä¼þÖеIJúÎï £¬ÔÚWebLogic12c¼°ÒÔÉÏ°æ±¾ÖÐĬÈϼ¯³Éµ½WebLogic°²×°°üÖÐ £¬¹¥»÷Õßͨ¹ýt3ЭÒé·¢ËͽṹµÄÐòÁл¯Êý¾Ý £¬ÄܹýÔì³ÉÃüÁîÖ´ÐеÄЧ¹û

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Atlassian_Confluence_Îļþ¶ÁÈ¡

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃAtlassianConfluence5.8.17֮ǰ°æ±¾ÖдæÔÚµÄÎļþ¶Áȡ©¶´½øÐй¥»÷µÄÐÐΪ £¬´Ó¶ø¶ÁÈ¡Ä¿±êϵͳµÄÃô¸ÐÎļþ¡£AtlassianonfluenceÊÇ°Ä´óÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×רҵµÄÆóҵ֪ʶ¹ÜÀíÓëЭͬÈí¼þ £¬Ò²¿ÉÒÔÓÃÓÚ¹¹½¨ÆóÒµWiKi¡£¸ÃÈí¼þ¿ÉʵÏÖÍŶӳÉÔ±Ö®¼äµÄЭ×÷ºÍ֪ʶ¹²Ïí¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zyxel·À»ðǽ_ÃüÁîÖ´ÐÐ[CVE-2022-30525][CNNVD-202205-3104]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃZyxel·À»ðǽ5.00-5.21°æ±¾´æÔÚµÄÃüÁîÖ´ÐЩ¶´½øÐй¥»÷ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£ZyxelUSGFLEXÊÇÖйúZyxel¹«Ë¾µÄÒ»¿î·À»ðǽ £¬¿ÉÒÔÌṩÁé»îµÄVPNÑ¡Ïî £¬ÎªÔ¶³ÌÊÂÇéºÍ¹ÜÀíÌṩÁé»îµÄÄþ¾²Ô¶³Ì·ÃÎÊ¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JBoss_JMXInvokerServlet·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-7501]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃJBoss6.4.0֮ǰ°æ±¾ÖÐÔÚ/invoker/JMXInvokerServletµÄ·´ÐòÁл¯Â©¶´ £¬¹¥»÷Õß¿ÉÒÔͨ¹ýApacheCommonsCollectionsÖеÄGadgetʵÏÖÈÎÒâ´úÂëÖ´ÐÐ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕß £¬ÔËÐкó £¬¿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾ £¬ÈçºóÃŵÈ¡£

¸üÐÂʱ¼ä£º

20221018

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Weblogic_Server_´úÂëÖ´ÐÐ[CVE-2021-2109][CNNVD-202101-1453]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracleWebLogic10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0°æ±¾´æÔڵĴúÂëÖ´ÐЩ¶´ £¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver £¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖмä¼þ £¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦Ó÷þÎñÆ÷¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJavaEnterprise³ß¶ÈµÄÄþ¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢²¿ÊðºÍ¹ÜÀíÖ®ÖС£

¸üÐÂʱ¼ä£º

20221018