Cisco IOS XEÈí¼þWeb UI¿çÕ¾µãÇëÇóαÔìÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-06-14Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-1904£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º8.8£¬£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÊÜÓ°ÏìµÄ°æ±¾
ÊÊÓÃÓÚCisco IOS XEÈí¼þ°æ±¾ÇÒÆôÓÃÁËHTTP Server¹¦Ð§µÄCisco×°±¸¡£¡£¡£¡£¡£¡£
Îó²î¸ÅÊö
Cisco IOS XEÊÇÃÀ¹ú˼¿Æ£¨Cisco£©¹«Ë¾µÄÒ»Ì×ΪÆäÍøÂç×°±¸¿ª·¢µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£Cisco IOS XE SoftwareÖеÄWeb UI±£´æCSRFÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¶ÔÊÜÓ°ÏìµÄϵͳ¾ÙÐпçÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÓÉÓÚÊÜÓ°ÏìÉè±¹ØÁ¬ÄWeb UIµÄCSRF±£»£»£»¤È±·¦¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý˵·þ½Ó¿ÚµÄÓû§×ñÕÕ¶ñÒâÁ´½ÓÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓÿÉÄÜÔÊÐí¹¥»÷ÕßʹÓÃÊÜÓ°ÏìÓû§µÄȨÏÞ¼¶±ðÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£¡£ÈôÊÇÓû§¾ßÓÐÖÎÀíȨÏÞ£¬£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ¸ü¸ÄÉèÖ㬣¬£¬£¬£¬£¬£¬Ö´ÐÐÏÂÁî»òÖØÐ¼ÓÔØÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
½ûÓÃHTTP Server¹¦Ð§¿ÉÏû³ý´ËÎó²îµÄ¹¥»÷ǰÑÔ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÊÇÊʵ±µÄ»º½â²½·¥£¬£¬£¬£¬£¬£¬£¬Ö±µ½¿ÉÒÔÉý¼¶ÊÜÓ°ÏìµÄ×°±¸¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó


¾©¹«Íø°²±¸11010802024551ºÅ