ÿÖÜÉý¼¶²¼¸æ-2021-10-12

°ä²¼¹¦·ò 2021-10-13

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_À¶º£×¿Ô½¼Æ·ÑÖÎÀíϵͳ_debug.php_ºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

À¶º£×¿Ô½¼Æ·ÑÖÎÀíϵͳ/debug.php´æÔÚδÊÚȨ½Ó¼û£¬£¬¸ÃÎļþÌṩһ¸öºÅÁîÖ´ÐеĽӿÚ£¬£¬¹¥»÷¿Éͨ¹ýŲÓøýӻ°±úÏÖÔ¶³ÌºÅÁîÖ´ÐС£

¸üй¦·ò£º

20211012



ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Confluence/JIRA_ËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2021-26085/CVE-2021-26086][CNNVD-202108-1398]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

AtlassianConfluenceÊÇAtlassian¹«Ë¾³öÆ·µÄרҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ£¬£¬¿ÉÓÃÓÚ¹¹½¨ÆóÒµÎÄ¿âµÈ¡£ConfluenceСÓÚ7.4.10£¬£¬7.5.0~7.12.3°æ±¾£¬£¬JiraСÓÚ8.5.14£¬£¬8.6.0~8.13.6£¬£¬8.14.0~8.16.1°æ±¾£¬£¬¶¼´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚ¶ÔÓû§µÄÊäÈëûÓнøÐÐÑϸñµÄ¹ýÂ˵¼Ö£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚδÊÚȨµÄÇé¿öÏ£¬£¬»ú¹Ø¶ñÒâÊý¾ÝÖ´ÐÐÎļþ¶ÁÈ¡¹¥»÷£¬£¬×îÖÕÔì³É·þÎñÆ÷²¿ÃÅÎļþÐÅϢй¶¡£

¸üй¦·ò£º

20211012


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½·ì϶[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ³¢ÊÔ¶ÔÖ÷ÕÅIPÖ÷»ú½øÐÐĿ¼´©Ô½·ì϶¹¥»÷³¢ÊÔµÄÐÐΪ¡£Ä¿Â¼´©Ô½·ì϶ÄÜʹ¹¥»÷ÕßÈÆ¹ýWeb·þÎñÆ÷µÄ½Ó¼ûÏÞ¶È£¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬£¬ËÁÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æ¶¨ÊÇÒ»ÌõͨÓù涨£¬£¬ÆäËû·ì϶£¨ÉõÖÁһЩ0day·ì϶£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£ÓÉÓÚÕý³£ÒµÎñÖÐͨ³£²»»á²úÉú´ËÊÂÎñÌØµãµÄÁ÷Á¿£¬£¬ËùÒÔ±ØÒªÖØµã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß½Ó¼ûÃô¸ÐÎļþ¡£

¸üй¦·ò£º

20211012