2020-11-10
°ä²¼¹¦·ò 2020-11-10ÊÂÎñÃû³Æ£º£º | HTTP_ľÂí_Downloader.APT-C-23_ÏÎ½Ó |
°²È«ÀàÐÍ£º£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½ APT-C-23ÏÂÔØÆ÷ľÂí ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË APT-C-23ÏÂÔØÆ÷ľÂí¡£¡£¡£¡£¡£APT-C-23ÏÂÔØÆ÷ľÂí ÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬£¬ÔËÐк󣬣¬Äܹ»ÆëÈ«½ÚÖÆ±»Ö²Èë»úе¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÖÆ±»Ö²Èë»úе¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_Nagios_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2019-20197] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | NagiosÊÇÒ»¿î¿ªÔ´µÄµçÄÔϵͳºÍÍøÂç¼à¶½¹¤¾ß£¬£¬ÄÜÓÐЧ¼à¿ØWindows¡¢LinuxºÍUnixµÄÖ÷»ú״̬£¬£¬»¥»»»ú·ÓÉÆ÷µÈÍøÂçÉèÖ㬣¬´òÓ¡»úµÈ¡£¡£¡£¡£¡£ÔÚϵͳ»ò·þÎñ״̬Ò쳣ʱ·¢³öÓʼþ»ò¶ÌÐű¨¾¯µÚÒ»¹¦·òÍ¨ÖªÍøÕ¾ÔËάÈËÔ±£¬£¬ÔÚ״̬¸´Ôºó·¢³öÕý³£µÄÓʼþ»ò¶ÌÐÅ֪ͨ¡£¡£¡£¡£¡£ÔÚNagios XI 5.6.9°æ±¾ÖУ¬£¬NagiosµÄ¡°»ã±¨¡±Ä£¿é´æÔÚ·ì϶£¬£¬¹¥»÷Õß¿Éͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâµÄ²Ù×÷ϵͳºÅÁî¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_Nodejs´úÂë×¢Èë·ì϶[CVE-2020-7699][CNNVD-202007-1739] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¸Ã·ì϶λÓÚexpress-fileupload npm×é¼þÖУ¬£¬¸Ã×é¼þ´Ónpm´¦ÏÂÔØÁ¿³¬¹ý730Íò£¬£¬ÆäÖв»º¬ÓдÓGitHub¡¢¾µÏñÍøÕ¾ºÍÆäËû¿Ë¡¿âÖÐÏÂÔØµÄ¡£¡£¡£¡£¡£¸Ã·ì϶ÊôÓÚPrototype Pollution£¨ÔÐÍ´«È¾£©·ì϶ÀàÐÍ£¬£¬ÕâÊÇJS´úÂëÖеij£¼û·ì϶ÀàÐÍ¡£¡£¡£¡£¡£ÓÉÓÚJSÊÇ»ùÓÚÔÐ͵Ä˵»°£¬£¬Ëµ»°ÖеÄÿ¸ö¶ÔÏ󡢺¯ÊýºÍÊý¾Ý½á¹¹¶¼ÓÐPrototypeÌØµã£¬£¬Äܹ»Í¨¹ý"_proto__"½øÐÐÅú¸Ä¡£¡£¡£¡£¡£Ê¹ÓÃÕâÖÖÉè¼Æ·ì϶µÄÔÐ͹¥»÷ͨ¹ý×¢Èë²»ÏàÊÊÓ¦µÄ¶ÔÏóÀàÐ͵½ÏÖÓеĶÔÏóÖÐÀ´Òý·¢ÃýÎ󣬣¬ÆæÈȵ¼ÖÂDoS¹¥»÷¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_ApacheKylin_ºÅÁî×¢Èë·ì϶[CVE-2020-1956][CNNVD-202005-1133] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | Apache Kylin ÊÇÃÀ¹úApache Èí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÉ¢²¼Ê½·ÖÎöÐÍÊý¾Ý²Ö¿â¡£¡£¡£¡£¡£¸Ã²úÆ·ÖØÒªÌṩ Hadoop/Spark Ö®É쵀 SQL ²éÎʽӿڼ°¶àά·ÖÎö£¨OLAP£©µÈÖ°ÄÜ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_XXL_JOB_δÊÚȨ½Ó¼ûÔ¶³ÌºÅÁîÖ´Ðзì϶ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | XXL-JOBÊÇÒ»¸öÇáÁ¿¼¶É¢²¼Ê½¹¤×÷µ÷¶Èƽ̨¡£¡£¡£¡£¡£Ä¬ÈÏÇé¿öÏÂXXL-JOBµÄRestful API½Ó¿Ú»òRPC½Ó¿ÚûÓÐÅäÖÃÈÏÖ¤´ëÊ©£¬£¬Î´ÊÚȨµÄ¹¥»÷Õ߿ɻú¹Ø¶ñÒâÒªÇ󣬣¬Ôì³ÉÔ¶³ÌÖ´ÐкÅÁ£¬Ö±½Ó½ÚÀñ·þÎñÆ÷¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º£º | HTTP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-14882][CVE-2020-14750] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâHTTPÒªÇóÀûÓø÷ì϶£¬£¬³É¹¦ÀûÓô˷ì϶¿ÉÄÜÊÕÊÜOracle WebLogic Server¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
ÊÂÎñÃû³Æ£º£º | HTTP_WebLogic_XXE×¢Èë·ì϶[CVE-2019-2887] |
°²È«ÀàÐÍ£º£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWebLogic_XXE×¢Èë·ì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£WebLogic_XXE×¢Èë·ì϶£¬£¬¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷,ËÁÒâÎļþ¶ÁÈ¡£¬£¬»ñÈ¡ÍøÕ¾µÄÃô¸ÐÊý¾ÝµÈ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
ÊÂÎñÃû³Æ£º£º | HTTP_WebLogic_Blind_XXE×¢Èë·ì϶[CVE-2019-2647] |
°²È«ÀàÐÍ£º£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWebLogic_Blind_XXE×¢Èë·ì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£WebLogic_Blind_XXE×¢Èë·ì϶£¬£¬¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3ºÍ̸ÖУ¬£¬Í¨¹ý¶ÔT3ºÍ̸ÖеÄpayload½øÐз´ÐòÁл¯£¬£¬´Ó¶øÊµÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |
ÊÂÎñÃû³Æ£º£º | DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÒªÇó |
°²È«ÀàÐÍ£º£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£¡£¡£ |
¸üй¦·ò£º£º | 20201110 |


¾©¹«Íø°²±¸11010802024551ºÅ