ÿÖÜÉý¼¶Í¨¸æ-2022-11-22
Ðû²¼Ê±¼ä 2022-11-22ÊÂÎñÃû³Æ£º TCP_ºóÃÅ_Beacon.Payload_ÅþÁ¬
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½Ä¿µÄIPÖ÷»úÊÔͼÏòÔ´IPÖ÷»ú´«ÊäºóÃÅ¡£¡£¡£¡£³£¼ûµÄBeacon°üÀ¨CobaltStrikeµÄBeacon£¬£¬ÒÔ¼°MetasploitµÄMeterpreterµÈ¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_Apache_Flink_СÓÚ1.11.2_í§ÒâÎļþ¶ÁÈ¡[CVE-2020-17519][CNNVD-202101-271]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ApacheFlink1.11.0,1.11.1,1.11.2°æ±¾ÔÊÐí¹¥»÷Õßͨ¹ýJobManagerÀú³ÌµÄRESTAPI¶ÁÈ¡JobManagerÍâµØÎļþϵͳÉϵÄÈκÎÎļþ£¨JobManagerÀú³ÌÄÜ»á¼ûµ½µÄ£©¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_SQLiteManager_1.2.0_Ŀ¼´©Ô½[CVE-2007-1232]
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSQLiteManagerµÄĿ¼´©Ô½Îó²î»á¼ûÃô¸ÐÎļþ¡£¡£¡£¡£SQLiteManager1.2.0°æ±¾ÖеÄĿ¼±éÀúÎó²îÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýSQLiteManager_currentThemeÖеÄ..¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Apache_CouchDB_JSON_ÏÂÁîÖ´ÐÐ[CVE-2017-12636][CNNVD-201711-486]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉÏApacheCouchDBµÄRestfulµÄAPI½Ó¿Ú±£´æµÄÎó²î£¬£¬½á¹¹¶ñÒâJsonÃûÌõÄÊý¾Ý£¬£¬´Ó¶øÊ¹·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâshellÏÂÁî¡£¡£¡£¡£CouchDBÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌ㬣¬JavaScript×÷ΪÅÌÎÊÓïÑÔ£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£¡£¡£¡£CouchDB½ÓÄÉ»ùÓÚErlangµÄJSONÆÊÎöÆ÷£¬£¬Óë»ùÓÚJavaScriptµÄJSONÆÊÎöÆ÷²î±ð£¬£¬CouchDB¿ÉÒÔÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇɫ֨¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ»á¼û¿ØÖÆ£¬£¬ÉõÖÁ°üÀ¨ÌåÏÖÖÎÀíÓû§µÄ_admin½ÇÉ«¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_ÖÂÔ¶OA_ajax.do_δÊÚȨ»á¼û
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÕýÔÚʹÓÃÖÂÔ¶OAV8.0ÒÔϰ汾µÄδÊÚȨÎó²î»ñȡȨÏÞÀ´¾ÙÐнøÒ»²½ÎļþÉÏ´«µÄ¹¥»÷£»£»£»£»ÖÂÔ¶OA°ì¹«×Ô¶¯»¯Èí¼þ£¬£¬ÓÃÓÚOA°ì¹«×Ô¶¯»¯Èí¼þµÄ¿ª·¢ÏúÊÛ¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_ÈôÒÀCMS_СÓÚ4.5.1_Îļþ¶ÁÈ¡[CNVD-2021-01931]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÈôÒÀCMS<4.5.1°æ±¾ÖеÄí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬µÇ¼ºǫ́ºó£¬£¬¿ÉÒÔ¶ÁȡЧÀÍÆ÷ÉϵÄí§ÒâÎļþ¡£¡£¡£¡£ÈôÒÀÖÎÀíϵͳÊÇ»ùÓÚSpringBootµÄȨÏÞÖÎÀíϵͳ¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange_Servers_ÏÂÁîÖ´ÐÐ[CVE-2022-40140][CVE-2022-41082]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ExchangeServerÊÇ΢Èí¹«Ë¾µÄÒ»Ì×µç×ÓÓʼþЧÀÍ×é¼þ,ÊǸöÐÂÎÅÓëÐ×÷ϵͳ¡£¡£¡£¡£¸Ãϵͳ±£´æÎó²î£¬£¬¿ÉÔÚ¾ÓÉExchangeServerÉí·ÝÑéÖ¤²¢ÇÒ¾ßÓÐPowerShell²Ù×÷ȨÏÞµÄÇéÐÎÏÂʹÓÃÕâЩÎó²î£¨×éºÏʹÓã©Ô¶³ÌÖ´ÐжñÒâ´úÂ룺CVE-2022-41040£ºMicrosoftExchangeServerЧÀÍÆ÷¶ËÇëÇóαÔì(SSRF)Îó²î£¬£¬CVE-2022-41082£ºMicrosoftExchangeServerÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯Èƹý[CVE-2019-2725][CNNVD-201904-1251]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º OracleWebLogicServerÊÇOracleCorporationÄ¿½ñ¿ª·¢µÄJavaEEÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£OracleWebLogicServer10.3.6.0.0¡¢OracleWebLogicServer12.1.3.0.0°æ±¾±£´æ·´ÐòÁл¯Îó²î£¬£¬¸ÃÎó²îÈÆ¹ýCVE-2019-2725²¹¶¡£¡£¡£¡£¬£¬Îó²î±£´æwls-wsatºÍbea_wls9_async_response×é¼þ£¬£¬Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄ¶ñÒâHTTPÇëÇ󣬣¬»ñȡЧÀÍÆ÷ȨÏÞ£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º SMTP_ÇÔÃÜľÂí_Snake_Keylogger_ÉÏ´«ÇÔÃÜÐÅÏ¢
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½SnakeKeyloggerÇÔÃÜľÂíÕýÔÚÏòÔ¶³ÌЧÀÍÆ÷ÉÏ´«ÇÔÃܵÄÖÖÖÖÐÅÏ¢¡£¡£¡£¡£Snake¶ñÒâÈí¼þÊÇÒ»ÖÖÒÔ.NET±à³ÌÓïÑÔʵÏÖµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£Í¨¹ýÍøÂç´¹ÂÚÓʼþ·Ö·¢¡£¡£¡£¡£SnakeÊÇÒ»ÖÖ¹¦Ð§¸»ºñµÄ¶ñÒâÈí¼þ£¬£¬¶ÔÓû§µÄÒþ˽ºÍÇå¾²×é³ÉÖØ´óÍþв¡£¡£¡£¡£Snake¾ßÓмͼ»÷¼üÒÔ¼°¼ôÌù°åÊý¾Ý¡¢ÆÁÄ»½ØÍ¼ºÍƾ֤͵ÇÔ¹¦Ð§¡£¡£¡£¡£Snake¿ÉÒÔ´Ó50¶à¸öÓ¦ÓóÌÐòÖÐÇÔȡƾ֤£¬£¬ÆäÖаüÀ¨FTP¿Í»§¶Ë¡¢Óʼþ¿Í»§¶Ë¡¢Í¨Ñ¶Æ½Ì¨ºÍWebä¯ÀÀÆ÷µÈÓ¦ÓóÌÐò¡£¡£¡£¡£SnakeÖ§³Öͨ¹ý¶àÖÖÐÒé¾ÙÐÐÉÏ´«Êý¾Ý£¬£¬ÀýÈçFTP¡¢SMTPºÍTelegramÈýÖÖ·½·¨ÉÏ´«ÇÔÈ¡µÄÐÅÏ¢¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_fileDownload.jsp_ÎļþÏÂÔØ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉϵķºÎ¢OAfileDownload.jsp±£´æµÄí§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý..\/À´Èƹý·ºÎ¢¶Ô../µÄÏÞÖÆ£¬£¬´Ó¶øÊµÏÖí§ÒâÎļþÏÂÔØ¡£¡£¡£¡£·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒÆ¶¯°ì¹«Õý̨¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_Ecology_weaver.eui.EuiServlet_ÎļþÉÏ´«
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉϵķºÎ¢OA_EcologyÉϺǫ́±£´æµÄÎļþÉÏ´«Îó²îÉÏ´«í§ÒâÎļþ£¬£¬´Ó¶ø»ñȡȨÏÞ¡£¡£¡£¡£·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒÆ¶¯°ì¹«Õý̨¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Apache_Spark_´úÂëÖ´ÐÐ[CVE-2020-9480]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ApacheSparkÊÇÒ»¸ö¿ªÔ´¼¯ÈºÔËËã¿ò¼Ü¡£¡£¡£¡£ÔÚApacheSpark2.4.5ÒÔ¼°¸üÔç°æ±¾ÖÐSparkµÄÈÏÖ¤»úÖÆ±£´æÈ±ÏÝ£¬£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¡£¡£¡£¹¥»÷ÕßʹÓøÃÎó²î£¬£¬¿ÉÔÚδÊÚȨµÄÇéÐÎÏ£¬£¬ÔÚÖ÷»úÉÏÖ´ÐÐÏÂÁ£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ºóÃÅ_Yakes.qwqÅþÁ¬
Çå¾²ÀàÐÍ£º ÆäËûÊÂÎñ
ÊÂÎñÐÎò£º ¸ÃÊÂÎñÅú×¢£¬£¬Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¸ÃÊÂÎñÔ´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅYakes.qwq¡£¡£¡£¡£Yakes.qwqÊÇ»ùÓÚIRCÐÒéµÄºóÃÅ£¬£¬ÔËÐк󣬣¬°Ñ×ÔÉí´úÂë²åÈ뵽ϵͳÕý³£Àú³Ì¡£¡£¡£¡£ÅþÁ¬Ô¶³ÌIRCÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷£¬£¬ÎüÊÕÆäÖ¸Á£¬²¢Ö´ÐС£¡£¡£¡£ÈçÏÂÔØ¶ñÒâÈí¼þ£¬£¬ÌᳫDDOS¹¥»÷¡£¡£¡£¡£±¾ºóÃÅÔËÐк󣬣¬Ê×ÏȽ¨Éè¼Ù½ÓÄÉÕ¾Îļþ¼Ð£¬£¬²¢¿½±´×ÔÉíµ½¸ÃÎļþ¼ÐÏ£¬£¬µÖ´ïÒþ²ØµÄÄ¿µÄ¡£¡£¡£¡£ÉèÖÃ×¢²á±í£¬£¬ÊµÏÖ¿ª»úÆô¶¯Òþ²ØÔÚ¼Ù½ÓÄÉÕ¾ÀïµÄºóÃųÌÐò¡£¡£¡£¡£ÎüÊÕ²¢Ö´ÐÐIRCЧÀÍÆ÷µÄÖ¸Áî¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ľÂíºóÃÅ_webshell_Altman_PHPÅþÁ¬
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýWebshellÖÎÀí¹¤¾ßAltman»á¼ûÄ¿µÄÖ÷»úÉϵÄÒ»¾ä»°Webshell£¬£¬´Ó¶ø»ñµÃÖ´ÐдúÂë¡¢ÉÏ´«ÏÂÔØÎļþµÈȨÏÞ¡£¡£¡£¡£Altman»ùÓÚ.Net4.0¿ª·¢£¬£¬Õû¸ö³ÌÐò½ÓÄÉmef²å¼þ¼Ü¹¹¡£¡£¡£¡£ÏÖÔÚÍê³ÉµÄ¹¦Ð§ÓУºShellÖÎÀí¡¢ÏÂÁîÖ´ÐС¢ÎļþÖÎÀí¡¢Êý¾Ý¿âÖÎÀí¡¢±àÂëÆ÷µÈ£¬£¬¾ç±¾ÀàÐÍÖ§³Öasp¡¢aspx¡¢php¡¢jsp¡¢python¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_Snews_CMS_ÎļþÉÏ´«¹¥»÷
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSnewsCMSÖеÄÎļþÉÏ´«Îó²î£¬£¬ÉÏ´«¶ñÒâÎļþ£¬£¬´Ó¶ø»ñµÃÄ¿µÄIPÖ÷»úµÄÖ´ÐдúÂë¡¢ÎļþÉÏ´«¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£¡£¡£¡£sNewsÊÇÒ»ÍêÈ«µØ×ÔÓɵġ¢Çкϱê×¼µÄ¡¢Ê¹ÓÃPHPºÍMySQLÇý¶¯µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_PHP_chrº¯Êý_webshellÎļþÉÏ´«
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃchrº¯Êý½á¹¹¶ñÒâÎļþÈÆ¹ýÒªº¦´Ê¼ì²â£¬£¬ÉÏ´«PHP¶ñÒâÎļþ£¬£¬´Ó¶ø»ñµÃÄ¿µÄIPÖ÷»úµÄÖ´ÐдúÂë¡¢ÎļþÉÏ´«¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_Zabbix_Server_trapper_ÏÂÁîÖ´ÐÐ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃZabbixµÄÎó²î¾ÙÐжñÒâÏÂÁîÖ´ÐС£¡£¡£¡£ZabbixÊÇÓÉAlexeiVladishev¿ª·¢µÄÒ»ÖÖÍøÂç¼àÊÓ¡¢ÖÎÀíϵͳ£¬£¬»ùÓÚServer-Client¼Ü¹¹¡£¡£¡£¡£ÔÚCVE-2017-2824ÖУ¬£¬ÆäServer¶Ëtrappercommand¹¦Ð§±£´æÒ»´¦´úÂëÖ´ÐÐÎó²î£¬£¬¶øÐÞ¸´²¹¶¡²¢²»ÍêÉÆ£¬£¬µ¼Ö¿ÉÒÔʹÓÃIPv6¾ÙÐÐÈÆ¹ý£¬£¬×¢Èëí§ÒâÏÂÁî¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_Alibaba_Canal-config_ÔÆÃÜÔ¿_ÐÅϢй¶
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º canalÊǰ¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌ⣬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄµØµã»á¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_¿ÉÒÉ·´µ¯shellÏÂÁî×¢Èë_¹¥»÷ʧ°Ü
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐBASH_·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£¡£¡£·´µ¯ÅþÁ¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀͶˣ¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£µ±Ö´ÐÐbash·´µ¯shellÏÂÁîÓÐÎóʱ£¬£¬»á·µ»Øbash:nojobcontrolinthisshell
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-YamlDotNetʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_yii·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPʹÓÃÄ¿µÄipÉÏyiiµÄ·´ÐòÁл¯Îó²î½á¹¹ÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌÏÂÁîÖ´ÐеÄÐÐΪ¡£¡£¡£¡£YiiÊÇÒ»¸ö¸ßÐÔÄܵÄPHP5µÄwebÓ¦ÓóÌÐò¿ª·¢¿ò¼Ü¡£¡£¡£¡£Í¨¹ýÒ»¸ö¼òÆÓµÄÏÂÁîÐй¤¾ßyiic¿ÉÒÔ¿ìËÙ½¨ÉèÒ»¸öwebÓ¦ÓóÌÐòµÄ´úÂë¿ò¼Ü£¬£¬¿ª·¢Õß¿ÉÒÔÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÌí¼ÓÓªÒµÂß¼£¬£¬ÒÔ¿ìËÙÍê³ÉÓ¦ÓóÌÐòµÄ¿ª·¢¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_ZendFramework_3.0_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2021-3007][CNNVD-202101-025]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPʹÓÃÄ¿µÄipÉÏZendFramework3.0µÄ·´ÐòÁл¯Îó²î½á¹¹ÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌÏÂÁîÖ´ÐеÄÐÐΪ¡£¡£¡£¡£ZENDZendFramework£¨ZF£©ÊÇÃÀ¹úZend£¨ZEND£©¹«Ë¾µÄÒ»Ì׿ªÔ´µÄPHP¿ª·¢¿ò¼Ü£¬£¬ËüÖ÷ÒªÓÃÓÚ¿ª·¢Web³ÌÐòºÍЧÀÍ¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_Swagger-api¹¤¾ß_Ãô¸ÐÎļþ»á¼û
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢»ùÓÚYAML¡¢JSONÓïÑÔµÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£¡£¡£¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£©£¬£¬Ïà¹ØÎļþ¼Ð±»»á¼ûÓÐÐÅϢй¶Σº¦¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬣¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122


¾©¹«Íø°²±¸11010802024551ºÅ