ÿÖÜÉý¼¶Í¨¸æ-2022-11-15
Ðû²¼Ê±¼ä 2022-11-15ʼþÃû³Æ£º | HTTP_ÐÅϢй¶_D-LinkDCS-2530LºÍDCS-2670L_¼à¿ØÃô¸ÐÐÅϢй¶[CVE-2020-25078][CNNVD-202009-083] |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚͨ¹ý·ÃÎÊD-LinkDCS-2530LºÍDCS-2670LµÄ"/config/getuser"»ñÈ¡¹ÜÀíÔ±ÐÅÏ¢¼°ÃÜÂë¡£D-LinkDCS-2530LºÍDCS-2670L¾ùÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÎÞÏßÍøÂçÐźÅÀ©Õ¹Æ÷¡£D-LinkDCS-2530L1.06.01Hotfix֮ǰ°æ±¾ºÍDCS-2670L2.02¼°Ö®Ç°°æ±¾´æÔÚÐÅϢ鶩¶´¡£ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_ÆäËû¿ÉÒÉÐÐΪ_SnakeYAML·´ÐòÁл¯_×Ô½ç˵TAG²ð·ÖÀàÃû |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿±êÖ÷»ú·¢ËÍ°üÂÞͨ¹ý×Ô½ç˵TAG£¬²ð·ÖjavaÀàÃûµÄSnakeYAMLÐòÁл¯Êý¾Ý£¬´Ó¶øÈƹý¼ì²âÉ豸¶ÔSnakeYAML·´ÐòÁл¯ÀûÓÃÁ´µÄ¼ì²â¡£SnakeYamlÊÇJavaÓÃÓÚ½âÎöYaml£¨YetAnotherMarkupLanguage£©¸ñʽÊý¾ÝµÄÀà¿â£¬ÆäÖпÉÒÔͨ¹ý×Ô½ç˵tag´¦ÖÃÆ÷²ð·ÖjavaÀàÃû |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | TCP_ÆäËû¿ÉÒÉÐÐΪ_java·´ÐòÁл¯_TC_RESETÔàÊý¾Ý |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿±êÖ÷»ú·¢ËÍ°üÂÞ´óÁ¿TC_RESETÔàÊý¾ÝµÄÐòÁл¯Êý¾Ý£¬´Ó¶øÈƹý¼ì²âÉ豸¶Ôjava·´ÐòÁл¯ÀûÓÃÁ´µÄ¼ì²â¡£TC_RESETÊÇjavaÐòÁл¯¸ñʽÖÐÓÃÓÚÖØÖÃReferenceIDµÄ±êʶ·û£¬¿ÉÒÔͨ¹ý¸Ã±êʶ·û½á¹¹°üÂÞÉó²ìÔàÊý¾ÝµÄjavaÐòÁл¯Á÷Á¿¡£ |
¸üÐÂʱ¼ä£º | 20221115 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_AxHostState-BinaryFormatterÀûÓÃÁ´_ysoserial¹¤¾ßÀûÓÃ_ÃüÁîÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢ÏÖµÄʵÓ÷¨Ê½ºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄ¼¯ºÏ£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂÀûÓÃ.NETÓ¦Ó÷¨Ê½Ö´Ðв»Äþ¾²µÄ¹¤¾ß·´ÐòÁл¯¡£Ö÷Çý¶¯·¨Ê½½ÓÊÜÓû§Ö¸¶¨µÄÃüÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½³ß¶ÈÊä³ö¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦Ó÷¨Ê½²»Äþ¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬½«×Ô¶¯µ÷ÓÃÁ´²¢µ¼ÖÂÃüÁîÔÚÓ¦Ó÷¨Ê½Ö÷»úÉÏÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Zabbix_СÓÚ4.4_δÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃZabbixСÓÚ4.4°æ±¾ÖдæÔÚµÄΪδÊÚȨ·ÃÎÊ©¶´£¬´Ó¶øÔÚδ¾ÊÚȨµÄÇé¿öÏ·ÃÎÊZabbix·þÎñÆ÷ÉϵÄÊý¾Ý£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Éó¼Æ_ÉÏ´«war°ü |
Äþ¾²ÀàÐÍ£º | Äþ¾²Éó¼Æ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«war°ü¡£war°üÊÇJavaWeb·¨Ê½´òµÄ°ü£¬Ò»¸öwar°ü¿ÉÒÔÀí½âΪÊÇÒ»¸öwebÏîÄ¿£¬ÀïÃæÊÇÏîÄ¿µÄËùÓй¤¾ß¡£ÒÔTomcatΪÀý£¬½«War°ü·ÅÖÃÔÚÆä\webapps\Ŀ¼Ï£¬È»ºóÆô¶¯Tomcat£¬Õâ¸ö°ü¾Í»á×Ô¶¯½âѹ£¬²¿Êð¡¢Ðû²¼µ½web·þÎñÖС£ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Oracle_Weblogic_console_ȨÏÞÈƹý[CVE-2020-14883][CNNVD-202010-997] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracleWebLogic10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0ºÍ14.1.1.0.0°æ±¾ÖдæÔÚµÄconsoleȨÏÞÈƹý©¶´£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ·ÇÊÚȨ·ÃÎÊweblogicconsole£¬Ö®ºó¿ÉÒÔʹÓÃCVE-2020-14882¿ØÖÆÄ¿±êϵͳȨÏÞ¡£¡£WeblogicÊÇÄ¿Ç°È«ÇòÊг¡ÉÏÓ¦ÓÃ×î¹ã·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬±»³ÆΪҵ½ç×î¼ÑµÄÓ¦Ó÷¨Ê½·þÎñÆ÷£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦Ó÷¨Ê½£¬Ö§³Öй¦Ð§£¬¿É½µµÍÔËÓª³É±¾£¬Ìá¸ßÐÔÄÜ£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÎï×éºÏ¡£ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Weblogic_Îļþ¶ÁÈ¡[CVE-2019-2615] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWeblogic10.3.6.0.0,12.1.3.0.0ºÍ12.2.1.3.0°æ±¾ÖдæÔÚµÄÈÎÒâÎļþ¶Áȡ©¶´£¬´Ó¶ø»ñÈ¡Ä¿±êÖ÷»úÃô¸ÐÎļþÄÚÈÝ¡£WeblogicÊÇÄ¿Ç°È«ÇòÊг¡ÉÏÓ¦ÓÃ×î¹ã·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬±»³ÆΪҵ½ç×î¼ÑµÄÓ¦Ó÷¨Ê½·þÎñÆ÷£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦Ó÷¨Ê½£¬Ö§³Öй¦Ð§£¬¿É½µµÍÔËÓª³É±¾£¬Ìá¸ßÐÔÄÜ£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÎï×éºÏ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache_Shiro_СÓÚ1.5.3_ȨÏÞÈƹý[CVE-2020-1957][CNNVD-202003-1579] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃApacheShiroСÓÚ1.5.3ÖÐȨÏÞÈƹý©¶´¡£¹¥»÷Õß¿ÉÒÔ¾«ÐĽṹ¶ñÒâµÄURL£¬ÀûÓÃApacheShiroºÍSpringBoot¶ÔURLµÄ´¦ÖõIJîÒ컯£¬¿ÉÒÔÈƹýApacheShiro¶ÔSpringBootÖеÄServletµÄȨÏÞ¿ØÖÆ£¬ÊµÏÖδÊÚȨ·ÃÎÊ¡£ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÃüÁî×¢Èë |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÃüÁî×¢È멶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬exportovpn½Ó¿Ú´æÔÚÃüÁî×¢È룬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20221115 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ÈôÒÀCMS_Ô¶³ÌÃüÁîÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ÈôÒÀºǫ́¹ÜÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄ¸ñʽ£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́¼Æ»®ÈÎÎñ´¦£¬¶ÔÓÚ´«ÈëµÄ"µ÷ÓÃÄ¿±ê×Ö·û´®"ûÓÐÈκÎУÑ飬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³Ìµ÷ÓÃjar°ü£¬´Ó¶øÖ´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20221115 |