2020-12-22

Ðû²¼Ê±¼ä 2020-12-23

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ColdFusion8_FCKEditor_ÎļþÉÏ´«Îó²î[CVE-2009-2265][CNNVD-200907-058]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CKSourceFCKeditor£¨ÏÖ³ÆCKEditor£©ÊDz¨À¼CKSource¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ£¬£¬£¬£¬£¬»ùÓÚÍøÒ³µÄÎÄ×ֱ༭Æ÷¡£¡£¸Ã±à¼­ÓþßÓÐÇáÁ¿»¯£¬£¬£¬£¬£¬Ò×ÓÚ×°ÖõÈÌØµã¡£¡£FCKeditorµÄ±à¼­Æ÷/filemanager/browser/default/connectors/php/connector.phpÄ£¿£¿£¿£¿£¿éÖб£´æµÄÎļþÉÏ´«ÏÞÖÆÎó²î£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÉÏ´«¶ñÒâÎļþ¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Xiaomi_MiRouter3_ÏÂÁîÖ´ÐÐÎó²î[CVE-2018-13023][CNNVD-201811-787]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XiaomiMiRouterÊÇÖйúСÃ׿Ƽ¼£¨Xiaomi£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£XiaomiMiRouter32.22.15°æ±¾ÖеÄwifi_access¶Ëµã±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâµÄÇëÇóʹÓøÃÎó²îÖ´ÐÐϵͳÃüÁî¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÊÂÎñÃû³Æ£º

HTTP_Zivif_PR115_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-17105][CNNVD-201712-147]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃZivif_PR115µÄÎó²î¾ÙÐÐÏÂÁîÖ´Ðй¥»÷£»£»£»£»£»ZivifPR115-204-P-RSÊÇÒ»¿îÍøÂçÉãÏñ»ú×°±¸¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÊÂÎñÃû³Æ

HTTP_ZyXEL_P660HN_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-18370][CNNVD-201905-075]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃZyXEL_P660HNµÄÏÂÁîÖ´ÐÐÎó²î¾ÙÐй¥»÷£»£»£»£»£»ZyXELP660HN-T1AÊÇÖйų́ÍåºÏÇÚ£¨ZyXEL£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£ZyXELP660HN-T1A£¨hardware2°æ±¾£¬£¬£¬£¬£¬TrueOnline¹Ì¼þ200AAJS3D0°æ±¾£©ÖеÄRemoteSystemLogת·¢¹¦Ð§±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Xiaomi_MiTV_ÏÂÁîÖ´ÐÐÎó²î[CVE-2018-16130][CNNVD-201811-797]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XiaomiMiRouterÊÇÖйúСÃ׿Ƽ¼£¨Xiaomi£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£XiaomiMiRouter32.22.15°æ±¾ÖеÄrequest_mitv¶Ëµã±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâÇëÇóÀ´ÊµÏÖÖ´ÐÐí§ÒâϵͳÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÊÂÎñÃû³Æ£º

HTTP_WordPress_Plugin_DZS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2014-9094][CNNVD-201411-506]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWordPress_Plugin_DZSµÄÎó²î¾ÙÐÐÏÂÁîÖ´ÐУ»£»£»£»£»WordPressÊÇʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬£¬£¬Óû§¿ÉÒÔÔÚÖ§³ÖPHPºÍMySQLÊý¾Ý¿âµÄЧÀÍÆ÷ÉϼÜÉèÊôÓÚ×Ô¼ºµÄÍøÕ¾¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_WordPress_Easy_WP_SMTPÈÕÖ¾Îļþ̽²â

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWordPressµÄEasy_WP_SMTP²å¼þÈÕ־̻¶ÔÚÍâ¾ÙÐÐδÊÚȨ»á¼û¼°ÃÜÂë¶ñÒâÐ޸컣»£»£»£»EasyWPSMTPÔÊÐíÄúÉèÖúÍͨ¹ýSMTPЧÀÍÆ÷·¢ËÍËùÓÐÍâ·¢µç×ÓÓʼþ¡£¡£ÕâÑù¿ÉÒÔ±ÜÃâÄúµÄµç×ÓÓʼþ½øÈëÊÕ¼þÈ˵ÄÀ¬»øÓʼþÎļþ¼Ð¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_XStream_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-26258][CVE-2020-26259][CNNVD-202012-1083]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XStreamСÓÚ1.4.15°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷Õß½öͨ¹ýʹÓÃÒÑ´¦Öóͷ£µÄÊäÈëÁ÷À´ÔËÐÐí§ÒâµÄShellÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20201222


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Confluence_Unauthenticated_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-3396]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_Confluence_δÊÚȨ_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬ConfluenceÊÇÒ»¸öרҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ£¬£¬£¬£¬£¬³£ÓÃÓÚ¹¹½¨ÆóÒµwiki¡£¡£ËüǿʢµÄ±à¼­ºÍÕ¾µãÖÎÀíÌØÕ÷Äܹ»×ÊÖúÍŶӳÉÔ±Ö®¼ä¹²ÏíÐÅÏ¢¡¢ÎĵµÐ­×÷¡¢ÕûÌåÌÖÂÛ£¬£¬£¬£¬£¬ÐÅÏ¢ÍÆËÍ¡£¡£Ê¹ÓøÃÎó²î¿ÉÒÔ¶ÁȡЧÀÍÆ÷ÉÏí§ÒâÎļþ£¬£¬£¬£¬£¬½ø¶ø¿ÉÒÔ°üÀ¨¶ñÒâÎļþÀ´Ö´ÐдúÂë¡£¡£¿£¿£¿£¿£¿ÉÄÜÔì³ÉÃô¸ÐÐÅϢй¶£¬£¬£¬£¬£¬Ð§ÀÍÆ÷±»¿ØÖƵÈÑÏÖØÐ§¹û¡£¡£

¸üÐÂʱ¼ä£º

20201222