ÿÖÜÉý¼¶²¼¸æ-2021-09-21

°ä²¼¹¦·ò 2021-09-22

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÎļþ½Ó¼û_³£¼û¶¨Ãû

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ³¢ÊÔ½Ó¼ûÖ÷ÕÅIPÖ÷»úÉϵĿÉÒÉÎļþµÄÐÐΪ¡£¡£´ËÊÂÎñ½ö¹©ÐÅÏ¢²Î¿¼£¬£¬²»´ú±íÕæÊµ¹¥»÷¡£¡£±ØÒªÈ·ÈϽӼûµÄÎļþÔÚÖ÷ÕÅIPÖ÷»úÉÏÊÇ·ñÕæÊµ´æÔÚ¡£¡£ÇÒ±ØÒªÈ·ÈÏÎļþÄÚÈÝÊÇ·ñΪ¶ñÒâÄÚÈÝ¡£¡£

¸üй¦·ò£º

20210921


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_TP-Link_TL-WR940N_´úÂëÖ´ÐÐ[CVE-2019-6989][CNNVD-201904-442]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

TP-LinkTL-WR940NºÍTP-LinkTL-WR941ND¶¼ÊÇÖйúÆÕÁª£¨TP-Link£©µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£TP-LINKTL-WR940NºÍTL-WR941NDÖдæÔÚ»º³åÇøÃýÎó·ì϶¡£¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬£¬Î´ÕýÈ·ÑéÖ¤Êý¾ÝÌìǵ£¬£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æµØÎ»ÉÏÖ´ÐÐÁËÃýÎóµÄ¶Áд²Ù×÷¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶µ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£¡£

¸üй¦·ò£º

20210921

 


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Gh0st_Shine_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£Gh0stÊdzÛÃûµÄ¿ªÔ´Ô¶¿Ø·¨Ê½£¬£¬Ö°Äܼ«¶È׳´ó¡£¡£ÓµÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢´´½¨¡¢É¾³ý£©¡¢¹ý³ÌÖÎÀí¡¢ÏµÍ³·þÎñ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢²é¿´ÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈÖ°ÄÜ£¬£¬Äܹ»ÆëÈ«½ÚÖÆ±»Ï°È¾»úе¡£¡£

¸üй¦·ò£º

20210921

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«É¨Ãè_ɨÃèÆ÷nessus

°²È«ÀàÐÍ£º

°²È«É¨Ãè

ÊÂÎñÃèÊö£º

NessusÊǼ«¶È׳´óµÄ·ì϶ɨÃèÆ÷£¬£¬¸Ã¹¤¾ßÔ̺¬×îеķì϶Êý¾Ý¿â£¬£¬¼ì²âËٶȿ죬£¬ÕýÈ·ÐԸߣ¬£¬ÊÇÉøÈë²âÊÔÖØÒª¹¤¾ßÖ®Ò»¡£¡£¸Ã¸æ¾¯×¢Ã÷¼ì²âµ½nessusɨÃèÆ÷ɨÃèÁ÷Á¿¡£¡£

¸üй¦·ò£º

20210921


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Optergy-Proton-Enterprise_ºÅÁî×¢Èë·ì϶[CVE-2019-7276][CNNVD-201906-284]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OptergyProtonEnterpriseÊÇÃÀ¹úOptergy¹«Ë¾µÄÒ»ÌׯóÒµ¹¹ÖþÖÎÀíϵͳ¡£¡£OptergyProtonEnterprise2.3.0a¼°Ö®Ç°°æ±¾ÖдæÔÚ°²È«·ì϶¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ֱ½Óµ¼º½µ½Î´±»¼Í¼µÄºóÞ籾£¬£¬»ñȡȫÊýµÄϵͳ½Ó¼ûȨÏÞ£¬£¬½ø¶øÒÔ×î¸ßȨÏÞÖ´ÐдúÂë¡£¡£

¸üй¦·ò£º

20210921

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_rConfig_System_ajaxArchiveFiles.phpÔ¶³ÌºÅÁîÖ´Ðзì϶[CVE-2019-19509][CNNVD-202001-144]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÀûÓÃrConfig_System_ajaxArchiveFiles.phpÔ¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£¡£rConfig3.9.3Öз¢ÏÖÁËÒ»¸öÎÊÌâ¡£¡£Ô¶³ÌÈÏÖ¤Óû§Äܹ»Í¨¹ýÏòajaxArchiveFiles.php·¢ËÍGETÒªÇóÖ±½ÓÖ´ÐÐϵͳºÅÁ£¬ÓÉÓÚpath²ÎÊýûÓйýÂ˾ʹ«µÝ¸øexecº¯Êý£¬£¬Õâ»áµ¼ÖºÅÁîÖ´ÐС£¡£

¸üй¦·ò£º

20210921

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_D-Link-DIR-818LW&DIR-822_ºÅÁî×¢Èë[CVE-2018-19986][CNNVD-201905-305]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

D-LinkDIR-822ºÍD-LinkDIR-818LW¶¼ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£D-LinkDIR-818LWRev.A2.05.B03ºÍDIR-822B1202KRb06Öеġ®RemotePort¡¯²ÎÊý´æÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£¡£¸Ã·ì϶ԴÓÚÍⲿÊäÈëÊý¾Ý»ú¹Ø²Ù×÷ϵͳ¿ÉÖ´ÐкÅÁî¹ý³ÌÖУ¬£¬ÍøÂçϵͳ»ò²úƷδÕýÈ·¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ºÅÁîµÈ¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨²Ù×÷ϵͳºÅÁî¡£¡£

¸üй¦·ò£º

20210921


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÖ÷ÕÅipÖ÷»úÖпÉÄܶ³öÔÚÍâµÄÃô¸ÐÎļþ¡£¡£

¸üй¦·ò£º

20210914

 


ÊÂÎñÃû³Æ£º

TCP_Java¶¯Ì¬Å²ÓÃ_java.lang.ProcessBuilder_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´Ö¸±êIPÕýÔÚʹÓÃJava¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£ÔÚJavaÖУ¬£¬·¨Ê½¿ª·¢ÈËԱͨ³£»áͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½Ö´ÐÐÍⲿµÄShellºÅÁî¡£¡£ProcessBuilderÊÇjava5.0ÒýÈëµÄ£¬£¬start()²½Öè·µ»ØProcessµÄÒ»¸öʵÀý¡£¡£Í¨³£ÔÚJavaÓйصÄÀûÓÃϵͳÖУ¬£¬ÈôÊÇ´¦ÖÃÍⲿºÅÁîÖ´ÐÐʱ£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâ¸ö·ì϶Զ³Ì×¢ÈëºÅÁî»ò´úÂë²¢Ö´ÐС£¡£ÖîÈçStruts2¡¢SpringÕâЩÀûÓÃÒѾ­±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬ÀýÈçOgnl±í°×ʽºÍSpEL±í°×ʽµÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¹¥»÷Õßͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½ÔÚ³öȱµãÀûÓÃÖÐÖ´ÐÐËÁÒâ´úÂë»òºÅÁ£¬½øÒ»²½ÆëÈ«½ÚÖÆÖ¸±ê·þÎñÆ÷¡£¡£³¢ÊÔÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£

¸üй¦·ò£º

20210914

 

 

ÊÂÎñÃû³Æ£º

TCP_Java¾²Ì¬Å²ÓÃ_java.lang.Runtime_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´Ö¸±êIPÕýÔÚʹÓÃJava¾²Ì¬Å²ÓÃjava.lang.Runtime·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£ÔÚJavaÖУ¬£¬·¨Ê½¿ª·¢ÈËԱͨ³£»áͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½Ê½Ö´ÐÐÍⲿµÄShellºÅÁî¡£¡£RuntimeÀàÊÇJava·¨Ê½µÄÔËÐÐʱ»·¾³£¬£¬¿ª·¢ÕßÄܹ»Í¨¹ýgetRuntime()²½Öè»ñÈ¡µ±Ç°RuntimeÔËÐÐʱ¶ÔÏóµÄÒýÓᣡ£Í¨³£ÔÚJavaÓйصÄÀûÓÃϵͳÖУ¬£¬ÈôÊÇ´¦ÖÃÍⲿºÅÁîÖ´ÐÐʱ£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâ¸ö·ì϶Զ³Ì×¢ÈëºÅÁî»ò´úÂë²¢Ö´ÐС£¡£ÖîÈçStruts2¡¢SpringÕâЩÀûÓÃÒѾ­±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬ÀýÈçOgnl±í°×ʽºÍSpEL±í°×ʽµÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¹¥»÷Õßͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½Ê½ÔÚ³öȱµãÀûÓÃÖÐÖ´ÐÐËÁÒâ´úÂë»òºÅÁ£¬½øÒ»²½ÆëÈ«½ÚÖÆÖ¸±ê·þÎñÆ÷¡£¡£³¢ÊÔÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£

¸üй¦·ò£º

20210921

 

 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_ÓÃÓÑNC_º¹Çà·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IP¿ÉÄÜÕýÔÚÀûÓÃÓÃÓÑNCµÄ·ì϶½øÐй¥»÷£»¹¥»÷Õßͨ¹ý»ú¹ØÓÃÓÑÌØ¶¨µÄ·ÓÉʵÏÖ´úÂëÖ´ÐС¢Îļþ¶ÁÈ¡µÈ²Ù×÷£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿØ¡¢ÐÐÒµ»¯½â¾ö¹æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯ÀûÓü¯³É¡±µÄÖÎÀíÒµÎñÀíÄî¶øÉè¼Æ£¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯ÀûÓÃϵͳ¡£¡£

¸üй¦·ò£º

20210921