ÿÖÜÉý¼¶Í¨¸æ-2022-11-29

Ðû²¼Ê±¼ä 2022-11-29
ÐÂÔöʼþ


ʼþÃû³Æ£º    HTTP_ÌáȨ¹¥»÷_Advantech_R-SeetNet_ÃüÁîÖ´ÐÐ[CVE-2021-21805]
Äþ¾²ÀàÐÍ£º    Äþ¾²Â©¶´
ʼþÃèÊö£º    AdvantechR-SeeNetv2.4.12(20.10.2020)µÄping.php½Å±¾¹¦Ð§ÖдæÔÚ²Ù×÷ϵͳÃüÁî×¢È멶´¡£ÌØÖƵÄHTTPÇëÇó¿ÉÄܵ¼ÖÂÈÎÒâ²Ù×÷ϵͳÃüÁîÖ´ÐС£¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´´¥·¢´Ë©¶´¡£
¸üÐÂʱ¼ä£º    20221129


ÐÞ¸Äʼþ

ʼþÃû³Æ£º    TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-14379]
Äþ¾²ÀàÐÍ£º    Äþ¾²Â©¶´
ʼþÃèÊö£º    JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´® £¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¹¥»÷Õß¿ÉÄÜÀûÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààehcache¹¥»÷Ä¿µÄIPÖ÷»ú¡£
¸üÐÂʱ¼ä£º    20221129

ʼþÃû³Æ£º    TCP_Ãô¸ÐÐÅϢй¶_Linux_netstat_ÃüÁîÖ´ÐлØÏÔ
Äþ¾²ÀàÐÍ£º    CGI¹¥»÷
ʼþÃèÊö£º    Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÃüÁîµÄ»ØÏÔÐÅÏ¢ £¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ £¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÃüÁîµÄȨÏÞ¡£
¸üÐÂʱ¼ä£º    20221129

ʼþÃû³Æ£º    TCP_ÌáȨ¹¥»÷_java.lang.RuntimeÃô¸ÐÀà_´úÂëÖ´ÐÐ
Äþ¾²ÀàÐÍ£º    Äþ¾²Â©¶´
ʼþÃèÊö£º    ¼ì²âµ½Ô´Ä¿±êIPÕýÔÚʹÓÃJava¾²Ì¬µ÷ÓÃjava.lang.Runtime·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£ÔÚJavaÖÐ £¬·¨Ê½¿ª·¢ÈËԱͨ³ £»áͨ¹ý¾²Ì¬µ÷ÓÃjava.lang.Runtime·½Ê½Ö´ÐÐÍⲿµÄShellÃüÁî¡£RuntimeÀàÊÇJava·¨Ê½µÄÔËÐÐʱ»·¾³ £¬¿ª·¢Õß¿ÉÒÔͨ¹ýgetRuntime()ÒªÁì»ñÈ¡µ±Ç°RuntimeÔËÐÐʱ¹¤¾ßµÄÒýÓá£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖÐ £¬Èç¹û´¦ÖÃÍⲿÃüÁîÖ´ÐÐʱ £¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË £¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâ¸ö©¶´Ô¶³Ì×¢ÈëÃüÁî»ò´úÂë²¢Ö´ÐС£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÔø¾­±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄÈÎÒâ´úÂëÖ´ÐЩ¶´¡£¹¥»÷Õßͨ¹ý¾²Ì¬µ÷ÓÃjava.lang.Runtime·½Ê½ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî £¬½øÒ»²½ÍêÈ«¿ØÖÆÄ¿±ê·þÎñÆ÷¡£ÊµÑéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£
¸üÐÂʱ¼ä£º    20221129

ʼþÃû³Æ£º    HTTP_Äþ¾²Â©¶´_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÃüÁî×¢Èë
Äþ¾²ÀàÐÍ£º    Äþ¾²Â©¶´
ʼþÃèÊö£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÃüÁî×¢È멶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖÐ £¬exportovpn½Ó¿Ú´æÔÚÃüÁî×¢Èë £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÃüÁî¡£
¸üÐÂʱ¼ä£º    20221129

ʼþÃû³Æ£º    HTTP_Äþ¾²Â©¶´_ÈôÒÀCMS_Ô¶³ÌÃüÁîÖ´ÐЩ¶´
Äþ¾²ÀàÐÍ£º    Äþ¾²Â©¶´
ʼþÃèÊö£º    ÈôÒÀºǫ́¹ÜÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü £¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄ¸ñʽ £¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́¼Æ»®ÈÎÎñ´¦ £¬¶ÔÓÚ´«ÈëµÄ"µ÷ÓÃÄ¿±ê×Ö·û´®"ûÓÐÈκÎУÑé £¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³Ìµ÷ÓÃjar°ü £¬´Ó¶øÖ´ÐÐÈÎÒâÃüÁî¡£
¸üÐÂʱ¼ä£º    20221129