ÿÖÜÉý¼¶²¼¸æ-2021-11-30

°ä²¼¹¦·ò 2021-12-10

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_QNAP-QTS_´úÂëÖ´ÐÐ[CVE-2017-6361][CNNVD-201702-940]

°²È«ÀàÐÍ£º£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢¡¢¡¢ÖÎÀí¡¢¡¢¡¢±¸·Ý£¬£¬¶àýÌåÀûÓü°°²È«¼à¿ØµÈÖ°ÄÜ¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º£º

20211130

 

 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_QNAP-QTS_ºÅÁîÖ´ÐÐ[CVE-2017-6360][CNNVD-201702-941]

°²È«ÀàÐÍ£º£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢¡¢¡¢ÖÎÀí¡¢¡¢¡¢±¸·Ý£¬£¬¶àýÌåÀûÓü°°²È«¼à¿ØµÈÖ°ÄÜ¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâºÅÁ£¬»ñÈ¡ÖÎÀíԱȨÏÞºÍÃô¸ÐÐÅÏ¢¡£

¸üй¦·ò£º£º

20211130

 

 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_QNAP-QTS_ºÅÁîÖ´ÐÐ[CVE-2017-6359][CNNVD-201702-942]

°²È«ÀàÐÍ£º£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢¡¢¡¢ÖÎÀí¡¢¡¢¡¢±¸·Ý£¬£¬¶àýÌåÀûÓü°°²È«¼à¿ØµÈÖ°ÄÜ¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡ÖÎÀíԱȨÏÞ£¬£¬Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º£º

20211130

 


ÊÂÎñÃû³Æ£º£º

 TCP_°²È«·ì϶_Hadoop_Yarn_RPCδÊÚȨ½Ó¼û·ì϶

°²È«ÀàÐÍ£º£º

·ÇÊÚȨ½Ó¼û/ȨÏÞÈÆ¹ý

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃHadoopYarnµÄ·ì϶½øÐÐδÊÚȨ½Ó¼û£»£»¶ÔÓÚ8032¶³öÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬£¬±àдÀûÓ÷¨Ê½Å²ÓÃyarnClient.getApplications()¼´¿É²é¿´ËùÓÐÀûÓÃÐÅÏ¢£»£»Hadoop×÷Ϊһ¸öÉ¢²¼Ê½ÍÆËãÀûÓÿò¼Ü£¬£¬ÖÖÀàÖ°ÄÜ·±¶à£¬£¬¶øHadoopYarn×÷ΪÆäÖ÷Ìâ×é¼þÖ®Ò»¡£

¸üй¦·ò£º£º

20211130

 


ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_Apache_CouchDB_JSON_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2017-12636][CNNVD-201711-486]

°²È«ÀàÐÍ£º£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ô´IPÉ豸ÕýÔÚÀûÓÃApacheCouchDBJSONÔ¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â£¬£¬×¨Ò»ÓÚÒ×ÓÃÐԺͳÉΪ"Æëȫӵ±§webµÄÊý¾Ý¿â"¡£CouchDB»áĬÈÏ»áÔÚ5984¶Ë¿ÚÊ¢¿ªRestfulµÄAPI½Ó¿Ú£¬£¬ÓÃÓÚÊý¾Ý¿âµÄÖÎÀíÖ°ÄÜ¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢Ìåʽ£¬£¬JavaScript×÷Ϊ²éÎÊ˵»°£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£CouchDBѡȡ»ùÓÚErlangµÄJSON½âÎöÆ÷£¬£¬Óë»ùÓÚJavaScriptµÄJSON½âÎöÆ÷·ÖÆç£¬£¬CouchDBÄܹ»ÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇÉ«·´¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ½Ó¼û½ÚÖÆ£¬£¬ÉõÖÁÔ̺¬°µÊ¾ÖÎÀíÓû§µÄ_admin½ÇÉ«¡£¶ñÒâ¹¥»÷ÕßÀûÓÃÕâÒ»Ö°Äܲ¢½áºÏCVE-2017-12636·ì϶£¬£¬Äܹ»Ê¹·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý½Ó¼û·þÎñÆ÷ÉϵÄËÁÒâshellºÅÁî¡£

¸üй¦·ò£º£º

20211130

 

 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_Netgear_Nighthawk_R7000δÊÚȨԶ³Ì´úÂëÖ´Ðзì϶[CVE-2021-31802]

°²È«ÀàÐÍ£º£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ô´IPÉ豸ÕýÔÚÀûÓÃNetgea·ÓÉÆ÷Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£ÔÚNETGEARR7000ÉÏ´æÔÚÒ»¸öÉí·ÝÑéÖ¤ÅÔ·°²È«·ì϶¡£·ì϶ÀûÓóɹ¦ºó£¬£¬Äܹ»rootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£

¸üй¦·ò£º£º

20211130

 

 

ÊÂÎñÃû³Æ£º£º

 HTTP_°²È«·ì϶_Primefaces_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2017-1000486][CNNVD-201801-112]

°²È«ÀàÐÍ£º£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

PrimeFacesÊÇÒ»¸ö¿ªÔ´Óû§½çÃæ(UI)×é¼þ¿â£¬£¬ÓÃÓÚ»ùÓÚJavaServerFacesµÄÀûÓ÷¨Ê½£¬£¬ÓÉÍÁ¶úÆä¹«Ë¾PrimeTekInformatics´´½¨¡£Primefaces5.x´æÔÚÈõ¼ÓÃÜ·ì϶£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ʵÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º£º

20211130

 


ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_D-Link_DWL-2600AP_²Ù×÷ϵͳºÅÁî×¢Èë·ì϶[CVE-2019-20499/CVE-2019-20500/CVE-2019-20501][CNNVD-202003-201/CNNVD-202003-205/CNNVD-202003-204]

°²È«ÀàÐÍ£º£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

D-LinkDWL-2600APÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß½ÓÈëµãÉ豸¡£D-LinkDWL-2600AP4.2.0.15RevA°æ±¾ÖдæÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£¹¥»÷Õ߿ɽèÖú±£ÁôÅäÖÃÖ°ÄÜÀûÓø÷ì϶ִÐÐËÁÒâµÄ²Ù×÷ϵͳºÅÁî¡£

¸üй¦·ò£º£º

20211130

 

 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_Terramaster_TOS_ºÅÁî×¢Èë·ì϶[CVE-2020-35665]

°²È«ÀàÐÍ£º£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

TerramasterTOSÊÇÖйúÀö½­ÊÐͼÃÀµç×Ó¼¼Êõ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾´æÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýÔÚÊÂÎñ²ÎÊýÖÐÔ̺¬makecvs.php×¢Èë²Ù×÷ϵͳºÅÁî¡£

¸üй¦·ò£º£º

20211130

 


ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_SQL_Server_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-0618][CNNVD-202002-496]

°²È«ÀàÐÍ£º£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS)£¬£¬ÊÇ´Ë¿ÌÊÀ½çÉÏ¿í·ºÊ¹ÓõÄÊý¾Ý¿âÖ®Ò»¡£¸Ã·ì϶ԴÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢Ë;«ÐÄ»ú¹ØµÄÒªÇ󣬣¬¿ÉÀûÓô˷ì϶ÔÚ±¨±í·þÎñÆ÷·þÎñÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º£º

20211130

 

 

ÊÂÎñÃû³Æ£º£º

HTTP_´úÂëÖ´ÐÐ_ÆïÊ¿CMSÔ¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-35339][CNNVD-202102-1295]

°²È«ÀàÐÍ£º£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÆïÊ¿CMSµÄ¡°ÍøÕ¾ÓòÃû¡±¶ÔÓ¦²ÎÊý½øÐдúÂëÖ´ÐвÙ×÷£»£»ÆïÊ¿È˲ÅϵͳÊÇÒ»Ïî»ùÓÚPHPMYSQLΪÖ÷Ì⿪·¢µÄÒ»Ì×Ãâ·Ñ¿ªÔ´×¨ÒµÈ˲ÅÕÐÆ¸ÏµÍ³¡£ÎªÐ¡ÎÒÇóÖ°ºÍÆóÒµÕÐÆ¸ÌṩÐÅÏ¢»¯½â¾ö¹æ»®,ÆïÊ¿È˲Åϵͳ¾ß±¸Ö´ÐÐЧÄܸߡ¢¡¢¡¢Ä£°åÇл»×ÔÓÉ¡¢¡¢¡¢ºó¶ÜÖÎÀíÖ°Äܽýݡ¢¡¢¡¢Ä£¿éÖ°ÄÜ׳´óµÈÌØµã¡£

¸üй¦·ò£º£º

20211130

 


ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_XStream_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-26217][CNNVD-202011-1441]

°²È«ÀàÐÍ£º£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

Xstream½â×éʱ´¦ÖõÄÁ÷Ô̺¬ÀàÐÍÐÅÏ¢ÒÔÖØÐ´´½¨ÒÔǰ±àдµÄ¶ÔÏó¡£XStreamÒò¶ø»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐÂʵÀý¡£¹¥»÷ÕßÄܹ»°Ñ³Ö´¦ÖùýµÄÊäÈëÁ÷²¢´úÌæ»ò×¢ÈëÄܹ»Ö´ÐÐËÁÒâshellºÅÁîµÄ¶ÔÏó¡£

¸üй¦·ò£º£º

20211130


Åú¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐкÅÁî·ì϶

°²È«ÀàÐÍ£º£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º£º

÷ÈħµçÓ°·¨Ê½(MaccmsPHP)ÊÇÒ»Ì×ѡȡPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÃÀÂúµÄ׳´óÊÓÆµµçӰϵͳ¡£ÃÀÂúÖ§³ÖÖÚ¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬£¬ÆëÈ«Ãâ·Ñ¿ªÔ´¡£¸Ã·ìÏ¶ÖØÒªµÄ²úÉúÔ­ÒòÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£

¸üй¦·ò£º£º

20211130