ÿÖÜÉý¼¶Í¨¸æ-2022-08-05
Ðû²¼Ê±¼ä 2022-08-05ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_GITEA_1.4.0_Îļþ¶ÁÈ¡ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | GiteaÊÇ´ÓgogsÑÜÉú³öµÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬£¬£¬£¬ÊÇÒ»¸öÀàËÆÓÚGithub¡¢GitlabµÄ¶àÓû§Git¿ÍÕ»ÖÎÀíÆ½Ì¨¡£¡£¡£Æä1.4.0°æ±¾ÖÐÓÐÒ»´¦Âß¼¹ýʧ£¬£¬£¬£¬µ¼ÖÂδÊÚȨÓû§¿ÉÒÔ´©Ô½Ä¿Â¼£¬£¬£¬£¬¶Áдí§ÒâÎļþ£¬£¬£¬£¬×îÖÕµ¼ÖÂÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ÌìÈÚÐÅ_ÉÏÍøÐÐΪÖÎÀíϵͳ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÌìÈÚÐÅÉÏÍøÖÎÀíϵͳµÄÎó²î¾ÙÐÐí§ÒâÏÂÁîÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_H3C_CVM_í§ÒâÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | H3CCVM(ÔÆÐéÄ⻯ÖÎÀíϵͳ)±£´æÒ»¸öǰ̨í§ÒâÎļþÉÏ´«Îó²î¡£¡£¡£ÓÉÓÚδ¶Ô´«²Î¾ÙÐÐÕýµ±ÐÔУÑ飬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹Êý¾Ý°üÉÏ´«í§ÒâÀàÐÍÎļþ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PbootCMS-parserIfLabel_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | PbootCMSÊÇÒ»¿î¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾¿ª·¢½¨ÉèÖÎÀíϵͳ¡£¡£¡£ÆäÖеÄparserIfLabelÒªÁì±£´æÄ£°å×¢ÈëÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»ñȡĿµÄÖ÷»úȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_×¢Èë¹¥»÷_ºì·«Ò½ÁÆÔÆ_OA_SQL×¢Èë |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ¹ãÖݺ췫¿Æ¼¼ÓÐÏÞ¹«Ë¾£¨ÒÔϼò³Æ£ººì·«¿Æ¼¼£©ÊÇÊ®ÐÛʦ¹¤¼¯ÍÅÖ®Ò»£¬£¬£¬£¬ÊÇÖйú´¬²°¼¯ÍÅÓÐÏÞ¹«Ë¾ÆìϹ㴬¹ú¼ÊÓÐÏÞ¹«Ë¾¿Ø¹ÉµÄ¸ßÐÂÊÖÒÕÆóÒµ¡£¡£¡£ºì·«iOfficeÒ½Ôº°æ±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡Êý¾Ý¿âÃô¸ÐÐÅÏ¢¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Roxy-WI-options.py_ÏÂÁîÖ´ÐÐ[CVE-2022-31137][CNNVD-202207-676] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | Roxy-WIÊÇÓÃÓÚÖÎÀíHaproxy¡¢NginxºÍKeepalivedЧÀÍÆ÷µÄWeb½çÃæ¡£¡£¡£ÆäÖÐ6.1.1.0֮ǰµÄoptions.py±£´æÎó²î£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇéÐÎÏÂÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬¿ØÖÆÏµÍ³È¨ÏÞ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢E-office-do_excel.php_ÎļþдÈë |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£¡£¡£ÆäÖÐ/do_excel.php½Ó¿Ú±£´æÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îдÈë¶ñÒâÎļþ£¬£¬£¬£¬Ö²Èëwebshell£¬£¬£¬£¬»ñȡĿµÄϵͳȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_º£¿£¿£¿£¿µÍþÊÓ×ÛºÏÔËÓªÖÎÀíÆ½Ì¨_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | º£¿£¿£¿£¿µÍþÊÓ×ÛºÏÔËÓªÖÎÀíÆ½Ì¨°üÀ¨fastjson×é¼þ£¬£¬£¬£¬·¢ËͶñÒâjsonÊý¾Ý¿ÉÒÔµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ͨ´ïOA_·ÇÊÚȨ»á¼û |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ͨ´ïOAÊÇÒ»Ìװ칫ϵͳ¡£¡£¡£ÓÉÓÚͨ´ïOAÖÐheader.inc.php±£´æÎó²î£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýÉϰ¶ÏÞÖÆ£¬£¬£¬£¬µ¼ÖÂδÊÚȨ»á¼û¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_Struts2_S2-061Ô¶³ÌÏÂÁîÖ´Ðй¥»÷[CVE-2020-17530/CVE-2021-31805][CNNVD-202012-449/CNNVD-202204-3223] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâµÄÇëÇ󣬣¬£¬£¬Òý·¢OGNL±í´ïʽÆÊÎö£¬£¬£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Laravel_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2021-3129] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | LaravelÊÇÒ»Ì×¾«Á·¡¢¿ªÔ´µÄPHPWeb¿ª·¢¿ò¼Ü£¬£¬£¬£¬Ö¼ÔÚʵÏÖWebÈí¼þµÄMVC¼Ü¹¹¡£¡£¡£µ±Laravel¿ªÆôÁËDebugģʽʱ£¬£¬£¬£¬ÓÉÓÚLaravel×Ô´øµÄIgnition×é¼þ¶Ôfile_get_contents()ºÍfile_put_contents()º¯ÊýµÄ²»Ç徲ʹÓ㬣¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÌᳫ¶ñÒâÇëÇ󣬣¬£¬£¬½á¹¹¶ñÒâLogÎļþ´¥·¢Phar·´ÐòÁл¯£¬£¬£¬£¬×îÖÕÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Seowon-Intech-SWC-9100-Routers_Ô¶³ÌÏÂÁîÖ´ÐÐ[CVE-2013-7179][CNNVD-201402-022] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | SeowonIntechSWC-9100RoutersÊǺ«¹úÈðÔªÒóÌØ£¨SeowonIntech£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£¡£¡£SeowonIntechSWC-9100·ÓÉÆ÷ÖеÄcgi-bin/diagnostic.cgiÎļþÖеÄping¹¦Ð§Öб£´æÊäÈëÑéÖ¤Îó²î¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú¡®ping_ipaddr¡¯²ÎÊýÖеÄshellÔª×Ö·ûʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | TCP_ÍÚ¿óľÂí_CoinMiner_ÃÅÂÞ±ÒJSON-RPCÐÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý2(XMR) |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò£º | ¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCÐÒéÒÉËÆÅ²ÓÃÁËÃÅÂÞ±ÒÍÚ¿óAPIº¯Êý¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃÐÒé¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£Ëü¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹ص쬣¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£ÃÅÂÞ±ÒÓ¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹ص쬣¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëÍÚ¿ó½Úµã½»»¥¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |
ÊÂÎñÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220805 |