ÿÖÜÉý¼¶Í¨¸æ-2023-01-03
Ðû²¼Ê±¼ä 2023-01-03
ÊÂÎñÃû³Æ£º | TCP_ľÂíºóÃÅ_SparkRat_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½SparkRatÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSparkRat¡£¡£¡£¡£SparkRatÊÇÒ»¸öGo±àдµÄ£¬£¬£¬ÍøÒ³UI¡¢¿çƽ̨ÒÔ¼°¶à¹¦Ð§µÄÔ¶³Ì¿ØÖÆºÍ¼à¿Ø¹¤¾ß£¬£¬£¬¿ÉÒÔËæÊ±ËæµØ¼à¿ØºÍ¿ØÖÆËùÓÐ×°±¸¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ejs_Ä£°å×¢Èë_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ö÷»úÕýÔÚÔâÊÜejsÄ£°å×¢Èë¹¥»÷£¬£¬£¬Node.jsejsÄ£¿£¿£¿£¿é¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂ룬£¬£¬ÕâÊÇÓÉÉèÖÃ[Éó²éÑ¡Ïî][Êä³öº¯ÊýÃû³Æ]ÖеÄЧÀÍÆ÷¶ËÄ£°å×¢ÈëȱÏÝÒýÆðµÄ¡£¡£¡£¡£Í¨¹ý·¢ËÍÌØÖÆµÄHTTPÇëÇóÒÔʹÓÃí§ÒâOSÏÂÁîÁýÕÖoutputFunctionNameÑ¡Ï£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_Éó¼ÆÊÂÎñ_Nacos_Ãô¸ÐÒ³Ãæ»á¼û |
Çå¾²ÀàÐÍ£º | Çå¾²Éó¼Æ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¿½ñÖ÷»úÕýÔÚÔâÊÜnacosÃô¸ÐÒ³Ãæ»á¼û£¬£¬£¬NacosÊÇDynamicNamingandConfigurationServiceµÄÊ××Öĸ¼ò³Æ£¬£¬£¬Ò»¸ö¸üÒ×ÓÚ¹¹½¨ÔÆÔÉúÓ¦ÓõĶ¯Ì¬Ð§ÀÍ·¢Ã÷¡¢ÉèÖÃÖÎÀíºÍЧÀÍÖÎÀíÆ½Ì¨¡£¡£¡£¡£NacosÓÃÓÚ·¢Ã÷¡¢ÉèÖúÍÖÎÀí΢ЧÀÍ¡£¡£¡£¡£NacosÌṩÁËÒ»×é¼òÆÓÒ×ÓõÄÌØÕ÷¼¯£¬£¬£¬×ÊÖúÄú¿ìËÙʵÏÖ¶¯Ì¬Ð§ÀÍ·¢Ã÷¡¢Ð§ÀÍÉèÖá¢Ð§ÀÍÔªÊý¾Ý¼°Á÷Á¿ÖÎÀí¡£¡£¡£¡£Nacos×ÊÖúÄú¸üѸËÙºÍÈÝÒ׵ع¹½¨¡¢½»¸¶ºÍÖÎÀí΢ЧÀÍÆ½Ì¨¡£¡£¡£¡£NacosÊǹ¹½¨ÒÔ¡°Ð§ÀÍ¡±ÎªÖÐÐĵÄÏÖ´úÓ¦Óüܹ¹(ÀýÈç΢ЧÀÍ·¶Ê½¡¢ÔÆÔÉú·¶Ê½)µÄЧÀÍ»ù´¡ÉèÊ©¡£¡£¡£¡£Nacos¹Ù·½ÔÚgithubÐû²¼µÄissueÖÐÅû¶AlibabaNacos±£´æÒ»¸öÓÉÓÚ²»µ±´¦Öóͷ£User-Agentµ¼ÖµÄδÊÚȨ»á¼ûÎó²î¡£¡£¡£¡£Í¨¹ý¸ÃÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ¾ÙÐÐí§Òâ²Ù×÷£¬£¬£¬°üÀ¨½¨ÉèÐÂÓû§²¢¾ÙÐеǼºó²Ù×÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_XStream_DOS[CVE-2022-41966] |
Çå¾²ÀàÐÍ£º | ¾Ü¾øÐ§ÀÍ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃxstreamÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸£»£»£»£»£»Xstream½â×éʱ´¦Öóͷ£µÄÁ÷°üÀ¨ÀàÐÍÐÅÏ¢ÒÔÖØÐ½¨ÉèÒÔǰ±àдµÄ¹¤¾ß¡£¡£¡£¡£XStreamÒò´Ë»ùÓÚÕâЩÀàÐÍÐÅÏ¢½¨ÉèÐÂʵÀý¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô¦Öóͷ£¹ýµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢Èë¿ÉÒÔÖ´ÐÐí§ÒâshellÏÂÁîµÄ¹¤¾ß¡£¡£¡£¡£XStreamÖб£´æ¾Ü¾øÐ§ÀÍÎó²î(CVE-2022-41966)£¬£¬£¬XStreamÔÚ½«XML·´ÐòÁл¯Îª¹¤¾ßʱ±£´æ¿ÍÕ»Òç³ö£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýʹÓÃÊäÈëÁ÷£¬£¬£¬Ê¹XStreamÔڵݹéÉ¢ÁÐÅÌËãʱ´¥·¢¿ÍÕ»Òç³ö£¬£¬£¬µ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Splunk_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | SplunkEnterpriseÊÇ»úеÊý¾ÝµÄÒýÇæ¡£¡£¡£¡£Ê¹ÓÃSplunk¿ÉÍøÂç¡¢Ë÷ÒýºÍʹÓÃËùÓÐÓ¦ÓóÌÐò¡¢Ð§ÀÍÆ÷ºÍ×°±¸ÌìÉúµÄ¿ìËÙÒÆ¶¯ÐÍÅÌËã»úÊý¾Ý¡£¡£¡£¡£¹ØÁª²¢ÆÊÎö¿çÔ½¶à¸öϵͳµÄÖØ´óÊÂÎñ¡£¡£¡£¡£»£»£»£»£»ñÈ¡ÐÂÌõÀíµÄÔËÓª¿É¼ûÐÔÒÔ¼°ITºÍÓªÒµÖÇÄÜ¡£¡£¡£¡£ÓÉÓÚSplunkEnterpriseÖÐSimpleXMLÒDZí°å±£´æ´úÂë×¢È룬£¬£¬¾ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿É½á¹¹ÌØÖÆµÄÊý¾Ý°ü£¬£¬£¬Í¨¹ýPDFµ¼³ö²Ù×÷´¥·¢í§Òâ´úÂëÖ´ÐС£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Webmin_ÏÂÁîÖ´ÐÐ[CVE-2019-15107] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_ÌáÈ¡¹¥»÷_Webmin_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-15107]¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£WebminÊÇÏÖÔÚ¹¦Ð§×îǿʢµÄ»ùÓÚWebµÄUnixϵͳÖÎÀí¹¤¾ß¡£¡£¡£¡£ÖÎÀíԱͨ¹ýä¯ÀÀÆ÷»á¼ûWebminµÄÖÖÖÖÖÎÀí¹¦Ð§²¢Íê³ÉÏìÓ¦µÄÖÎÀíÐж¯¡£¡£¡£¡£ÔÚWebmin<=1.920µÄ°æ±¾ÖУ¬£¬£¬¸ÃÎó²îÓÉÓÚpassword_change.cgiÎļþÔÚÖØÖÃÃÜÂ빦ЧÖб£´æÒ»¸ö´úÂëÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²îÔÊÐí¶ñÒâµÚÈý·½ÔÚȱÉÙÊäÈëÑéÖ¤µÄÇéÐÎ϶øÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_IceWarp_WebClient_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | IceWarp,Inc.ÊÇÒ»¼ÒλÓڽݿ˹²ºÍ¹ú²¼À¸ñµÄÈí¼þ¹«Ë¾¡£¡£¡£¡£Ëü¿ª·¢ÁËIceWarpMailServer£¬£¬£¬ÕâÊÇÒ»ÏîÃæÏòÖÐСÐÍÆóÒµµÄµç×ÓÓʼþ¡¢ÐÂÎźÍÐ×÷ЧÀÍ¡£¡£¡£¡£ÆäÖиÃϵͳµÄWebClientbasic²¿·Ö±£´æÎó²î£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâpayloadÔì³É´úÂëÖ´ÐС£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_YouPHPTube_Encoder_ÏÂÁîÖ´ÐÐ[CVE-2019-5127] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | YouPHPTubeEncoderÊÇYouPHPTubeµÄ±àÂëÆ÷²å¼þ£¬£¬£¬¸Ã²å¼þ¿ÉÔÚYouPHPTubeÖÐÌṩ±àÂëÆ÷¹¦Ð§¡£¡£¡£¡£Ê¹ÓÃÕßÔÚ×Ô¼ºµÄЧÀÍÆ÷ÉÏ×°Öò¢Ê¹ÓÃYouPHPTubeEncoderÒÔÈ¡´úµÚÈý·½¹«¹²±àÂëÆ÷ЧÀÍÆ÷£¬£¬£¬¿ÉÒÔ¸ü¿ìËÙ±ã½ÝµÄ±àÂë×Ô¼ºµÄÊÓÆµ£¬£¬£¬²¢ÇÒ»¹¿ÉÒÔʹÓÃ˽Óз½·¨¶Ô×Ô¼ºµÄÊÓÆµ¾ÙÐбàÂë¡£¡£¡£¡£ÔÚYouPHPTubeEncoder2.3ÖУ¬£¬£¬±£´æÎÞÐèÉí·ÝÑéÖ¤µÄÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËͰüÀ¨Ìض¨²ÎÊýµÄWebÇëÇóÀ´´¥·¢ÕâЩÎó²î¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jinja2_SSTI_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | jinja2Ä£°åÖÐʹÓÃ{{}}Óï·¨ÌåÏÖÒ»¸ö±äÁ¿£¬£¬£¬ËüÊÇÒ»ÖÖÌØÊâµÄռλ·û¡£¡£¡£¡£µ±Ê¹ÓÃjinja2¾ÙÐÐäÖȾµÄʱ¼ä£¬£¬£¬Ëü»á°ÑÕâÐ©ÌØÊâµÄռλ·û¾ÙÐÐÌî³ä/Ìæ»»£¬£¬£¬jinja2Ö§³ÖpythonÖÐËùÓеÄPythonÊý¾ÝÀàÐͺñÈÁÐ±í¡¢×ֶΡ¢¹¤¾ßµÈ¡£¡£¡£¡£Jinja2äÖȾʱ²»µ«½öÖ»¾ÙÐÐÌî³äºÍÌæ»»£¬£¬£¬»¹Äܹ»Ö´Ðв¿·Ö±í´ïʽ¡£¡£¡£¡£Èô¹¥»÷ÕßÄÜÀֳɿØÖÆ´«ÈëµÄ±í´ïʽ£¬£¬£¬Ôò¿ÉÒÔͨ¹ýЧÀͶËÄ£°æäÖȾÔÚÄ¿µÄÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2021-2135][CNNVD-201804-803] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogic·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÓ¦ÓóÌÐòЧÀÍÆ÷£¬£¬£¬ÊÇÒ»¸ö»ùÓÚJavaEE¼Ü¹¹µÄWebÖÐÐļþ¡£¡£¡£¡£WebLogic±£´æJava·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJavaÐòÁл¯¶ñÒâ´úÂ룬£¬£¬µ±WebLogicÖ´ÐÐJava·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ÓÉÓÚWebLogicÐÞ¸´Îó²î½ÓÄÉÁ˺ÚÃûµ¥¹ýÂË»úÖÆ£¬£¬£¬ÓÐʱ¼ä¿ÉÄܵ¼ÖÂÎó²îÐÞ¸´²»³¹µ×еķ´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²îƵ·¢£¬£¬£¬Òò´ËÇëÇ×½ü¹Ø×¢Oracle¹Ù·½Ðû²¼µÄÎó²î²¹¶¡£¡£¡£¡£¬£¬£¬ÊµÊ±¾ÙÐв¹¶¡¸üÐÂÒÔÈ·±£Ð§ÀÍÆ÷Çå¾²¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Atlassian_Crowd_ÎļþÉÏ´«[CNNVD-201905-1031] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÕýÔÚʹÓÃAtlassianCrowdÔÚuploadplugin.action´¦µÄÎļþÉÏ´«Îó²î¾ÙÐй¥»÷£¬£¬£¬ÉÏ´«¶ñÒâjar²å¼þ£¬£¬£¬´Ó¶øÊ¹µÃAtlassianCrowdÖ±½Ó×°Öøòå¼þ´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£AtlassianCrowdÊÇÒ»Ì×»ùÓÚWebµÄµ¥µãµÇ¼ϵͳ¡£¡£¡£¡£¸ÃϵͳΪ¶àÓû§¡¢ÍøÂçÓ¦ÓóÌÐòºÍĿ¼ЧÀÍÆ÷ÌṩÑéÖ¤¡¢ÊÚȨµÈ¹¦Ð§¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_XStream_·´ÐòÁл¯[CVE-2013-7285] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | XStreamʵÏÖÁËÒ»Ì×ÐòÁл¯ºÍ·´ÐòÁл¯»úÖÆ£¬£¬£¬½¹µãÊÇͨ¹ýConverterת»»Æ÷À´½«XMLºÍ¹¤¾ßÖ®¼ä¾ÙÐÐÏ໥µÄת»»£¬£¬£¬XStream·´ÐòÁл¯Îó²îµÄ±£´æÊÇÓÉÓÚXStreamÖ§³ÖÒ»¸öÃûΪDynamicProxyConverterµÄת»»Æ÷£¬£¬£¬¸Ãת»»Æ÷¿ÉÒÔ½«XMLÖÐdynamic-proxy±êÇ©ÄÚÈÝת»»³É¶¯Ì¬ÊðÀíÀ๤¾ß£¬£¬£¬¶øµ±³ÌÐòŲÓÃÁËdynamic-proxy±êÇ©ÄÚµÄinterface±êǩָÏòµÄ½Ó¿ÚÀàÉùÃ÷µÄÒªÁìʱ£¬£¬£¬¾Í»áͨ¹ý¶¯Ì¬ÊðÀí»úÖÆÊðÆÊÎö¼ûdynamic-proxy±êÇ©ÄÚhandler±êǩָ¶¨µÄÀàÒªÁ죻£»£»£»£»Ê¹ÓÃÕâ¸ö»úÖÆ£¬£¬£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâµÄXMLÄÚÈÝ£¬£¬£¬µ±¹¥»÷Õß´ÓÍⲿÊäÈë¸Ã¶ñÒâXMLÄÚÈݺ󼴿ɴ¥·¢·´ÐòÁл¯Îó²î¡¢µÖ´ïí§Òâ´úÂëÖ´ÐеÄÄ¿µÄ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬣¬£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬£¬£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230103 |