ÿÖÜÉý¼¶Í¨¸æ-2022-12-27
Ðû²¼Ê±¼ä 2022-12-27
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Cacti_ÃüÁîÖ´ÐÐ[CVE-2022-46169][CVE-2022-46169] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | CactiÏîÄ¿ÊÇÒ»¸ö¿ªÔ´Æ½Ì¨£¬¿ÉΪÓû§Ìṩǿ´óÇÒ¿ÉÀ©Õ¹µÄ²Ù×÷¼à¿ØºÍ¹ÊÕϹÜÀí¿ò¼Ü¡£ÓÉÓÚremote_agent.phpÖеÄcasePOLLER_ACTION_SCRIPT_PHPÔÚʹÓÃproc_openº¯Êýʱδ¶Ô´«ÈëµÄpoller_id²ÎÊý×öÑϸñ¹ýÂË£¬¹¥»÷Õ߿ɽṹÂú×ãÌõ¼þµÄpayload¶ÔÏà¹ØÄ¿±êϵͳ½øÐÐÃüÁî×¢È룬µ¼ÖÂÔ¶³ÌÃüÁîÖ´ÐС£Ó°Ï췶Χ£ºCacti==1.2.22 |
¸üÐÂʱ¼ä£º | 20221227 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Hessain_lite_´úÂëÖ´ÐÐ[CVE-2022-39198] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | HessianÊÇÒ»ÖÖ¶¯Ì¬ÀàÐ͵Ķþ½øÖÆÐòÁл¯ºÍWeb·þÎñÐÒ飬רΪÃæÏò¹¤¾ßµÄ´«Êä¶øÉè¼Æ¡£Hessian-lite×î³õÊǹٷ½hessianµÄApachedubboembed°æ±¾£¬Õâ¸öÄ£¿éºóÀ´´ÓDubboÖÐÊèÉ¢³öÀ´¡£DubboµÄËùÓзÖÖ§£º2.5.x¡¢2.6.x(×Ô2.6.3)ºÍ2.7.x¶¼ÒÀÀµÓÚËü¡£ÓÉÓÚHessian-liteÔÚ½øÐÐÐòÁл¯Êý¾Ý´«Êäʱ´æÔÚ©¶´£¬¹¥»÷Õß¿Éͨ¹ý¾«ÐĹ¹½¨µÄpayloadÈƹý¹Ù·½µÄºÚÃûµ¥ÀàÏÞÖÆ£¬´Ó¶øÔÚÄ¿±êÖ÷»úÉÏÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20221227 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_ThinkPhp_lang_pearcmd_Îļþ°üÂÞ[CVE-2022-47945] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃThinkphp¶àÓïÑÔ¹¦Ð§ÖдæÔÚµÄĿ¼´©Ô½½øÐÐÎļþ°üÂÞ¹¥»÷¡£ThinkPHPÊÇÒ»¸öÔÚÖйúʹÓý϶àµÄPHP¿ò¼Ü¡£ÔÚÆä6.0.13°æ±¾¼°ÒÔÇ°£¬´æÔÚÒ»´¦µ±µØÎļþ°üÂÞ©¶´¡£µ±¶àÓïÑÔÌØÐÔ±»¿ªÆôʱ£¬¹¥»÷Õß¿ÉÒÔʹÓÃlang²ÎÊýÀ´°üÂÞÈÎÒâPHPÎļþ£¬²¢½øÒ»²½Í¨¹ýpearcmd.phpʵÏÖÈÎÒâÎļþдÈë¡£ |
¸üÐÂʱ¼ä£º | 20221227 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_fuelCMS_1.4.1_´úÂëÖ´ÐÐ[CVE-2018-16763] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | FUELCMSÊÇÒ»¿î»ùÓÚCodeIgniterµÄÄÚÈݹÜÀíϵͳ¡£Æä1.4.1°æ±¾´æÔÚ©¶´£¬ÔÊÐíͨ¹ýpages/select/Ö´ÐÐphp´úÂ룬Õâ¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20221227 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_DrayTek_Ô¤Éí·ÝÑéÖ¤_ÃüÁîÖ´ÐÐ[CVE-2020-8515] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½¹¥»÷ÕßÀûÓÃDrayTekÔ¤Éí·ÝÑéÖ¤´¦µÄÁ½´¦ÃüÁî×¢È멶´½øÐй¥»÷µÄÐÐΪ¡£DrayTekÊÇÒ»¼ÒÔÚÖйúÉú²ú·À»ðǽ£¬VPNÉ豸£¬Â·ÓÉÆ÷£¬WLANÉ豸µÈµÄÖÆÔìÉÌ¡£¸Ã©¶´Ô´ÓÚ/cgi-bin/mainfunction.cgi·¨Ê½Î´ÕýÈ·¹ýÂËkeyPath×ֶκÍrtick×Ö¶ÎÆäÖеÄÌØÊâ×Ö·û£¬¹¥»÷Õß¿ÉÀûÓø鶴²»¾¹ýÉí·ÝÑéÖ¤ÒÔrootȨÏÞÖ´ÐдúÂë¡£¹¥»÷Àֳɣ¬¿ÉÒÔrootȨÏÞÖ´ÐдúÂë |
¸üÐÂʱ¼ä£º | 20221227 |
ʼþÃû³Æ£º | TCP_Éó¼Æʼþ_java.lang.ProcessBuilder_´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´Ä¿±êIPÕýÔÚʹÓÃJava¶¯Ì¬µ÷ÓÃjava.lang.ProcessBuilder·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£ÔÚJavaÖУ¬·¨Ê½¿ª·¢ÈËԱͨ³£»áͨ¹ý¶¯Ì¬µ÷ÓÃjava.lang.ProcessBuilder·½Ê½Ö´ÐÐÍⲿµÄShellÃüÁî¡£ProcessBuilderÊÇjava5.0ÒýÈëµÄ£¬start()ÒªÁì·µ»ØProcessµÄÒ»¸öʵÀý¡£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬Èç¹û´¦ÖÃÍⲿÃüÁîÖ´ÐÐʱ£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâ¸ö©¶´Ô¶³Ì×¢ÈëÃüÁî»ò´úÂë²¢Ö´ÐС£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÔø¾±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄÈÎÒâ´úÂëÖ´ÐЩ¶´¡£¹¥»÷Õßͨ¹ý¶¯Ì¬µ÷ÓÃjava.lang.ProcessBuilder·½Ê½ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐÈÎÒâ´úÂë»òÃüÁ½øÒ»²½ÍêÈ«¿ØÖÆÄ¿±ê·þÎñÆ÷¡£ÊµÑéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20221227 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_ThinkPhp_lang_Îļþ°üÂÞ[CVE-2022-47945] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃThinkphp¶àÓïÑÔ¹¦Ð§ÖдæÔÚµÄĿ¼´©Ô½½øÐÐÎļþ°üÂÞ¹¥»÷¡£hinkPHPÊÇÒ»¸öÔÚÖйúʹÓý϶àµÄPHP¿ò¼Ü¡£ÔÚÆä6.0.13°æ±¾¼°ÒÔÇ°£¬´æÔÚÒ»´¦µ±µØÎļþ°üÂÞ©¶´¡£µ±¶àÓïÑÔÌØÐÔ±»¿ªÆôʱ£¬¹¥»÷Õß¿ÉÒÔʹÓÃlang²ÎÊýÀ´°üÂÞÈÎÒâPHPÎļþ¡£ |
¸üÐÂʱ¼ä£º | 20221227 |