ÿÖÜÉý¼¶Í¨¸æ-2021-10-26

Ðû²¼Ê±¼ä 2021-10-27

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁî×¢Èë[CVE-2017-7876][CNNVD-201704-779]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

QNAPSystemsQNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬£¬£¬£¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£QNAPQTS4.2.6build20170517֮ǰµÄ°æ±¾Öб£´æÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î×¢ÈëÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_VMware_vCenter_Server_ЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î[CVE-2021-21973][CNNVD-202102-1559]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃVMwarevCenterServerЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚVMwarevCenterServer²å¼þÖжÔÓû§ÌṩµÄÊäÈëÑéÖ¤²»µ±£¬£¬£¬£¬£¬£¬Î´¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖÆµÄHTTPÇëÇ󣬣¬£¬£¬£¬£¬ÓÕÆ­Ó¦ÓóÌÐòÏòí§ÒâϵͳÌᳫÇëÇóʵÏÖÄÚÍøÉ¨Ã裬£¬£¬£¬£¬£¬»ñÈ¡ÄÚÍøÐÅÏ¢£¬£¬£¬£¬£¬£¬µ¼ÖÂÐÅϢй¶¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jetty_WEB-INF_ÐÅϢй¶Îó²î[CVE-2021-34429]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

EclipseJetty°æ±¾9.4.37-9.4.42¡¢10.0.1-10.0.5ºÍ11.0.1-11.0.5£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃһЩ±àÂë×Ö·û½á¹¹ÌØÊâµÄURIÀ´»á¼ûWEB-INFĿ¼µÄÄÚÈÝ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211019

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-LinkDSL-2640U&DSL-2540U_ÏÂÁîÖ´ÐÐ[CVE-2018-5371][CNNVD-201801-545]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

D-LinkDSL-2640U×°±¸£¨¹Ì¼þΪIM_1.00ºÍME_1.00£©ºÍDSL-2540U×°±¸£¨¹Ì¼þΪME_1.00£©ÉϵÄdiag_ping.cmdÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýHTTPGETÇëÇóµÄipaddr×Ö¶ÎÖеÄshellÔª×Ö·ûÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Subrion-CMS_´úÂëÖ´ÐÐ[CVE-2018-19422][CNNVD-201811-628]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SubrionCMSÊÇSubrionÍŶӿª·¢µÄÒ»Ì×»ùÓÚPHPµÄÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¡£¡£¡£¸Ãϵͳ¿É±»¼¯³Éµ½ÍøÕ¾£¬£¬£¬£¬£¬£¬²¢Ö§³Ö¶àÖÖÀ©Õ¹²å¼þµÈ¡£¡£¡£¡£SubrionCMS4.2.1°æ±¾ÖеÄ/panel/uploads±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ.htaccessÎļþûÓÐեȡ¶ÔphtºÍpharÎļþµÄÖ´ÐвÙ×÷¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú.pht»ò.pharÎļþʹÓøÃÎó²îÖ´ÐÐí§ÒâµÄPHP´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_OpenMRS_´úÂëÖ´ÐÐ[CVE-2018-19276][CNNVD-201902-602]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OpenMRSÊÇÃÀ¹úOpenMRS¹«Ë¾µÄÒ»Ì׿ªÔ´µÄµç×Ó²¡Àúϵͳ¡£¡£¡£¡£OpenMRSPlatform2.24.0֮ǰ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Billion_5200W-T_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-18372][CNNVD-201905-077]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Billion5200W-T·ÓÉÆ÷ÔÚʱ¼äÉèÖù¦Ð§Öб£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¸ÃÎó²îλÓÚtools_time.aspÒ³Ãæ£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

UDP_DD-WRT_»º³åÇøÒç³öÎó²î[CVE-2021-27137]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

DD-WRTÊÇÒ»¸ö»ùÓÚLinuxµÄÎÞÏß·ÓÉÈí¼þ¡£¡£¡£¡£¸ÃÎó²î£¬£¬£¬£¬£¬£¬Í¨¹ý»º³åÇøÒç³ö¿ÉÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬µ¼ÖÂÖ÷»úÓб»½ÓÊܵÄΣº¦¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Billion_5200W-T_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-18369][CNNVD-201905-073]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Billion5200W-T·ÓÉÆ÷ÔÚÔÚadv_remotelog.aspÎļþÖб£´æÎ´¾­Éí·ÝÑéÖ¤µÄÏÂÁî×¢Èë¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_OTRS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-16921][CNNVD-201711-917]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÔÚOTRS6.0.xÖÁ6.0.1¡¢OTRS5.0.xÖÁ5.0.24ºÍOTRS4.0.xÖÁ4.0.26ÖУ¬£¬£¬£¬£¬£¬ÒÔÊðÀíÉí·ÝµÇ¼OTRSµÄ¹¥»÷Õß¿ÉÒÔʹÓÃ±íµ¥²ÎÊý£¨ÓëPGPÏà¹Ø£©²¢ÔÚOTRS»òWebЧÀÍÆ÷Óû§µÄȨÏÞÏÂÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_HPEÖÇÄÜÖÎÀíÖÐÐÄ_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-7184][CNNVD-202010-863]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

HPEIntelligentManagementCenterÊÇÃÀ¹ú»ÝÆÕÆóÒµ¹«Ë¾£¨HewlettPackardEnterprise£¬£¬£¬£¬£¬£¬HPE£©µÄÒ»Ì×ÍøÂçÖÇÄÜÖÎÀíÖÐÐĽâ¾ö¼Æ»®¡£¡£¡£¡£¸Ã½â¾ö¼Æ»®¿ÉÌṩÕû¸öÍøÂç¹æÄ£µÄ¿ÉÊÓÐÔ£¬£¬£¬£¬£¬£¬ÊµÏÖ¶Ô×ÊÔ´¡¢Ð§ÀͺÍÓû§µÄÖÜÈ«ÖÎÀí¡£¡£¡£¡£HPEIntelligentManagementCenter(iMC)7.3֮ǰ°æ±¾±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚviewbatchtaskresultdetailfact±í´ïʽÓïÑÔ×¢ÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_FreePBXÇå¾²ÈÆ¹ýÎó²î[CVE-2019-19006][CNNVD-201911-1264]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃFreePBXÇå¾²ÈÆ¹ýÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£FreePBX£¨Ç°³ÆAsteriskManagementPortal£©ÊÇFreePBXÏîÄ¿µÄÒ»Ì×ͨ¹ýGUI£¨»ùÓÚÍøÒ³µÄͼÐλ¯½Ó¿Ú£©ÉèÖÃAsterisk£¨IPµç»°ÏµÍ³£©µÄ¹¤¾ß¡£¡£¡£¡£FreePBX115.0.16.26¼°Ö®Ç°°æ±¾¡¢14.0.13.11¼°Ö®Ç°°æ±¾ºÍ13.0.197.13¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµÄ»á¼û¿ØÖÆ¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÈÆ¹ýÃÜÂëÉí·ÝÑéÖ¤²¢»á¼ûЧÀ͹¦Ð§¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-Link_DIR-859Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-17621][CNNVD-201912-1224]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃD-Link_DIR-859Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£D-LinkDIR-859×°±¸LAN²ãÖзºÆðδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_VMware_NSX_SD-WAN_Edge_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-6961][CNNVD-201805-1140]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃVMware_NSX_SD-WANEdgeµÄÎó²î¾ÙÐй¥»÷£»£»£» £»VMwareSD-WANEdgeÊÇÒ»¿îÁã½Ó´¥Ê½ÆóÒµ¼¶×°±¸,Äܹ»ÒÔ¾­ÓÉÓÅ»¯µÄ·½·¨Îª×¨ÓС¢¹«¹²»ò»ìÏýÓ¦ÓÃ,ÒÔ¼°ÅÌËãºÍÐéÄ⻯ЧÀÍÌṩÇå¾²ÅþÁ¬¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ZyXEL-CloudCNM-SecuManager_´úÂë×¢Èë[CVE-2020-15348][CNNVD-202006-1754]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZyxelCNMSecuManager3.1.0ºÍ3.1.1°æ±£´æÓ²±àÂëÉñÃØ¡¢Éí·ÝÑé֤ɥʧ¡¢ºóÃźÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£Í¨¹ýdelete_cpes_by_ids¾ÙÐдúÂë×¢Èë¿ÉÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬£¬Î£º¦Ö÷»úÇå¾²¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_FCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃFCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£FCKeditorÊÇ¿ªÔ´µÄÍøÒ³±à¼­Æ÷£¬£¬£¬£¬£¬£¬±»ÖÚ¶à´øÓб༭¹¦Ð§µÄÍøÕ¾»òÕßCMSʹÓᣡ£¡£¡£FCKeditor±£´æFCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓôËÎó²îÉÏ´«í§ÒâÀàÐÍÎļþ£¬£¬£¬£¬£¬£¬»ñȡĿµÄÍøÕ¾µÄwebshell£¬£¬£¬£¬£¬£¬½øÒ»²½»ñÈ¡ÍøÕ¾¿ØÖÆÈ¨¡£¡£¡£¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026


 

ÊÂÎñÃû³Æ£º

HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026


ɾ³ýÊÂÎñ


1¡¢HTTP_ͨÓÃ_unicodeÈÆ¹ý

2¡¢SMB_¾Ü¾øÐ§ÀÍ_Winnuke_¹¥»÷[CVE-1999-0153]