ÿÖÜÉý¼¶Í¨¸æ-2021-11-02
Ðû²¼Ê±¼ä 2021-11-09ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_UEditor±à¼Æ÷_í§ÒâÎļþÉÏ´«Îó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃUEditor±à¼Æ÷µÄcontroller.ashxÒ³ÃæÉÏ´«Îļþ¡£¡£¡£¡£UEditorÊÇÓɰٶÈWEBǰ¶ËÑз¢²¿¿ª·¢µÄËù¼û¼´ËùµÃµÄ¿ªÔ´¸»Îı¾±à¼Æ÷£¬£¬£¬£¬£¬¸ÃÒ³Ãæ±£´æÒ»¸öÉÏ´«í§ÒâÎļþµÄÎó²î£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýαÔìǰ׺Õýµ±µÄÎļþÃû£¬£¬£¬£¬£¬ÖÐÐÄÌí¼Ó½Ø¶Ï·ûºÅ£¬£¬£¬£¬£¬Ê¹µÃí§ÒâÎļþ¾ù¿ÉÉÏ´«¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_×¢Èë¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-24616][CNNVD-202008-1195] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÏòÄ¿µÄip¾ÙÐз´ÐòÁл¯¹¥»÷£»£»£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | TCP_ľÂí_NetWire±äÖÖ_Ô¶¿ØÄ¾Âí |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWin32.NetWire¡£¡£¡£¡£Win32.NetWireÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÔ¶¿ØÄ¾Âí£¬£¬£¬£¬£¬¿ÉÔ¶³Ì¿ØÖÆÊܺ¦Ö÷»úÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃÊÂÎñ_·¢Ã÷ʹÓÃunicode±àÂë |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | JavaĬÈϵıàÂë·½·¨ÎªUnicode£¬£¬£¬£¬£¬ÔÚjavaÓïÑԺͲ¿·Ö.net³ÌÐòÖУ¬£¬£¬£¬£¬unicode±àÂë¿É±»×Ô¶¯´¦Öóͷ£ÆÊÎö³É×Ö·û´®¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_URLȨÏÞÈÆ¹ýÎó²î[CVE-2020-1957][CNNVD-202003-1579] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬£¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬ÊÚȨµÈ¡£¡£¡£¡£¹ØÓÚApacheShiro1.5.1֮ǰµÄ°æ±¾£¬£¬£¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬£¬£¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÏòÄ¿µÄip¾ÙÐз´ÐòÁл¯¹¥»÷£»£»£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_VantageVelocity_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2020-9020][CNNVD-202002-889] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | IterisVantageVelocityFieldUnitÊÇÃÀ¹úIteris¹«Ë¾µÄÒ»¿îõè¾¶¼à²âÏÖ³¡×°±¸¡£¡£¡£¡£IterisVantageVelocityFieldUnit2.3.1°æ±¾¡¢2.4.2°æ±¾ºÍ3.0°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£ÔÚVantageVelocity²úÆ·SynchronizeWithNTPServer´¦£¬£¬£¬£¬£¬Óû§¿ÉÒÔÉèÖÃÖ¸¶¨µÄntpЧÀÍÆ÷µØµã¡£¡£¡£¡£ÓÉÓÚδ¶ÔÓû§Ð´ÈëµÄhtmlNtpServer±äÁ¿¹ýÂË£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâÄÚÈÝ´¥·¢ÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Terramaster-TOS-exportUser.php_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-15568][CNNVD-202101-2598] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | TerramasterTOSÊÇÖйúÌúÍþÂí£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬£¬£¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NASЧÀÍÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£¡£TerraMasterTOSbefore4.1.29±£´æÊäÈëÑéÖ¤¹ýʧÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÎÞЧµÄ²ÎÊý¼ì²é£¬£¬£¬£¬£¬µ¼Ö´úÂëÒÔroot×¢Èë¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Master-IP-CAM-01_ÏÂÁî×¢ÈëÎó²î[CVE-2020-10971][CNNVD-202005-271][CVE-2019-8387][CNNVD-201902-725][CVE-2019-8387][CNNVD-201902-725] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | MasterIPCAM01ÊÇÒ»¿îÍøÂçÉãÏñ»ú¡£¡£¡£¡£MasterIPCAM013.3.4.2103°æ±¾Öб£´æÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬£¬£¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨ÏÂÁî¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_InoERP_0.7.2_Ô¶³Ì´úÂëÖ´ÐÐ/ÊäÈëÑéÖ¤¹ýʧÎó²î[CVE-2020-28870] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | InoERPÊÇÒ»Ì×»ùÓÚPHPµÄ¿ªÔ´ÆóÒµÖÎÀíϵͳ¡£¡£¡£¡£InoERPÖб£´æÊäÈëÑéÖ¤¹ýʧ/Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úƷδ¶ÔÊäÈëµÄÊý¾Ý¾ÙÐÐ׼ȷµÄÑéÖ¤£¬£¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Ç徲ɨÃè_WEBɨÃèÆ÷ÐÐΪ |
Çå¾²ÀàÐÍ£º | Ç徲ɨÃè |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPµØµãµÄÖ÷»úÕýÔÚʹÓÃWEBɨÃ蹤¾ß¶ÔÄ¿µÄIPµØµã¾ÙÐÐÎó²îɨÃè¡£¡£¡£¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×öЧÀÍɨÃè¡¢Îó²î²âÊԵȡ£¡£¡£¡£Í¨¹ýÎó²îɨÃ裬£¬£¬£¬£¬¿ÉÒÔ×Ô¶¯¿ìËÙ̽²âһЩ³£¼ûÎó²îÇéÐΣ¬£¬£¬£¬£¬µ±±£´æÎó²îʱ±ãÓÚºóÐø¾ÙÐÐʹÓù¥»÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_Win32.DTLoaderÏÂÔØÕßľÂí_ÏÂÔØ¶ñÒâPayload |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½DTLoaderÏÂÔØÕßľÂíÕýÔÚÏÂÔØ¶ñÒâPayload¡£¡£¡£¡£DTLoaderÊÇÒ»¸öÏÂÔØÕßľÂí£¬£¬£¬£¬£¬ÈÏÕæÏÂÔØ¶ñÒâ´úÂ룬£¬£¬£¬£¬ÏÂÔØµÄ¶ñÒâ´úÂëÓÐAgentTesla,NanoCoreµÈ¡£¡£¡£¡£Ê¹ÓÃDTLoaderC#ÓïÑÔ±àд¶ø³É£¬£¬£¬£¬£¬Ò»Ñùƽ³£¾ÓÉ»ìÏý¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃÊÂÎñ_·¢Ã÷¶à´Îunicode±àÂëÐÐΪ |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | JavaĬÈϵıàÂë·½·¨ÎªUnicode£¬£¬£¬£¬£¬ÔÚjavaÓïÑԺͲ¿·Ö.net³ÌÐòÖУ¬£¬£¬£¬£¬unicode±àÂë¿É±»×Ô¶¯´¦Öóͷ£ÆÊÎö³É×Ö·û´®¡£¡£¡£¡£¶à´Îunicode±àÂë¿ÉÄÜΪ¹¥»÷ÕßʵÑéÈÆ¹ý¼ì²â×°±¸µÄÐÐΪ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_FastjsonÎó²î_hex±àÂëʹÓà |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£fastjson¿É½ÓÊܲ¢ÆÊÎöhex±àÂëÄÚÈÝ£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉʹÓÃhex±àÂëÈÆ¹ý¼ì²â×°±¸¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_GitLab_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2021-22205][CNNVD-202104-1685] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | GitLabÊÇÓÉGitLabInc.¿ª·¢£¬£¬£¬£¬£¬Ê¹ÓÃMITÔÊÐíÖ¤µÄ»ùÓÚÍøÂçµÄGit¿ÍÕ»ÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬¾ßÓÐissue¸ú×Ù¹¦Ð§¡£¡£¡£¡£ËüÊÇʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬²¢ÔÚ´Ë»ù´¡ÉϴÆðÀ´µÄwebЧÀÍ¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚGitLabûÓÐ׼ȷµÄ´¦Öóͷ£´«ÈëµÄͼÏñÎļþ£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉʹÓøÃÎó²î½á¹¹¶ñÒâÊý¾ÝÖ´ÐÐÔ¶³ÌÏÂÁ£¬£¬£¬£¬×îÖÕÔì³ÉЧÀÍÆ÷Ãô¸ÐÐÔÐÅϢй¶¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_GitLab_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î [CVE-2021-22205][CNNVD-202104-1685] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | GitLabÊÇÓÉGitLabInc.¿ª·¢£¬£¬£¬£¬£¬Ê¹ÓÃMITÔÊÐíÖ¤µÄ»ùÓÚÍøÂçµÄGit¿ÍÕ»ÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬¾ßÓÐissue¸ú×Ù¹¦Ð§¡£¡£¡£¡£ËüÊÇʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬²¢ÔÚ´Ë»ù´¡ÉϴÆðÀ´µÄwebЧÀÍ¡£¡£¡£¡£¸ÃÎó²îÊÇÓÉÓÚGitLabûÓÐ׼ȷµÄ´¦Öóͷ£´«ÈëµÄͼÏñÎļþ£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉʹÓøÃÎó²î½á¹¹¶ñÒâÊý¾ÝÖ´ÐÐÔ¶³ÌÏÂÁ£¬£¬£¬£¬×îÖÕÔì³ÉЧÀÍÆ÷Ãô¸ÐÐÔÐÅϢй¶¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÊÂÎñÃû³Æ£º | DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó2 |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ÍÚ¿óľÂíÊÔͼÅþÁ¬ÓòÃûЧÀÍÆ÷ÆÊÎö¿ó³ØµØµã¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£¡£ÍÚ¿óľÂíʵÑéÅþÁ¬¿ó³Ø£¬£¬£¬£¬£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬£¬£¬£¬£¬ÏûºÄCPU×ÊÔ´¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_fastjson_1.2.47_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | FastjsonÊÇÒ»¸öJava¿â£¬£¬£¬£¬£¬¿ÉÒÔ½«Java¹¤¾ßת»»ÎªJSONÃûÌ㬣¬£¬£¬£¬fastjsonÔÚ1.2.47ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211102 |