ÿÖÜÉý¼¶²¼¸æ-2021-12-28

°ä²¼¹¦·ò 2021-12-28

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©³¨ÆðÍ·ÀûÓÃ[MS17-010][CNNVD-201703-726]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅÖ÷»ú½øÐÐMS17-010·ì϶ÀûÓõÄÐÐΪ£¬£¬¸Ã½×¶ÎΪ·ì϶ÀûÓõijõʼ½×¶Î¡£¡£¡£MicrosoftWindowsÊÇ΢Èí°ä²¼µÄ¼«¶ÈÊ¢ÐеIJÙ×÷ϵͳ¡£¡£¡£ÈôÊǹ¥»÷ÕßÏòMicrosoft·þÎñÆ÷·¢Ë;­¾«ÐÄ»ú¹ØµÄ»ûÐÎÒªÇó°ü£¬£¬Äܹ»»ñȡָ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬£¬²¢ÇÒÆëÈ«½ÚÖÆÖ¸±êϵͳ¡£¡£¡£¹¥»÷Õ߯ðÍ·½øÐÐMS17-010·ì϶ÀûÓ㬣¬ÔÚ±¾»ú´æÔÚ·ì϶µÄÇé¿öÏ£¬£¬ÔÚÀûÓÃʵÏÖºó¹¥»÷Õß¿ÉÄÜÆëÈ«½ÚÖÆÖ÷»ú¡£¡£¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Spring-Data-REST-PATCHÒªÇó_Ô¶³ÌÖ´ÐдúÂë[CVE-2017-8046]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

2017Äê9ÔÂ21ÈÕ£¬£¬Ê¢ÐеÄJava¿ò¼Üspring±»·¢ÏÖÒ»¸ö¸ßΣ·ì϶£¬£¬·ì϶CVE±àºÅΪCVE-2017-8046¡£¡£¡£ºÚ¿ÍÄܹ»ÀûÓø÷ì϶Զ³ÌÖ´ÐкÅÁ£¬Ê¹ÓÃÁËspring¿ò¼ÜµÄÒµÎñ´æÔڸ߰²È«·çÏÕ¡£¡£¡£SpringDataRestÊÇSpringData¿ò¼ÜµÄÆäÖÐÒ»¸ö×é¼þ£¬£¬SpringDataRest¿É¹¹½¨RestWeb£¬£¬SpringDataRest¶ÔPATCH²½Öè´¦Öò»µ±£¬£¬µ¼Ö¹¥»÷Õß¿ÉÄÜÀûÓÃJSONÊý¾ÝÔì³ÉRCE¡£¡£¡£ÐÔÖÊ»¹ÊÇÓÉÓÚSpringµÄSPEL½âÎöµ¼ÖµÄRCE¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Intellian_Satellian_Aptus_WebÔ¶³Ì´úÂëÖ´ÐÐ[CVE-2020-7980]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

Intellian Satellian Aptus Web ÊÇÒ»¸ö½ÚÖÆÌ¨ÏµÍ³¡£¡£¡£ÔÚIntellian Aptus Web 1.24 ֮ǰµÄ°æ±¾ÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý JSON Êý¾ÝÖÐµÄ Q ×Ö¶ÎÏò/cgi-bin/libagent.cgi Ö´ÐÐËÁÒâ OS ºÅÁî¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_ºÅÁîÖ´ÐÐ_Alcatel-Lucent_OmniPCX_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2007-3010][CNNVD-200709-257]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃAlcatelR7.1°æ±¾ÒÔǰµÄ·ì϶½øÐкÅÁîÖ´ÐУ»£»£»Alcatel_OmniPCXEnterpriseÊÇÒ»ÖÖÕë¶Ô´óÖÐÐÍÆóÒµ¡¢¡¢±ö¹Ý¡¢¡¢ºô½ÐÖÐÐĵɽ»»¥Ê½Í¨Ñ¶½â¾ö¹æ»®¡£¡£¡£¸Ã½â¾ö¹æ»®½«´«Í³µÄµç»°Ö°ÄܺͶԻùÓÚÒòÌØÍøµÄÓïÒôͨѶ¼°¶àýÌåͨѶµÄÖ§³ÖÏà½áºÏ¡£¡£¡£AlcatelOmniPCXEnterpriseÊÇ»ùÓÚÒµ½ç³ß¶ÈµÄÊ¢¿ªÐÍ¡¢¡¢É¢²¼Ê½Í¨ÕÛ·þÎñÆ÷£¬£¬ºÏÓÃÓÚ´óÖÐÐÍÆóÒµµÄͨѶҵÎñ¡£¡£¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ÐÅϢй¶·ì϶[CVE-2018-6910][CNNVD-201802-949]

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

DesdevDedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈݰ䲼¡¢¡¢±à×ë¡¢¡¢ÖÎÀí¼ìË÷µÈÓÚÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¡£¡£DesdevDedeCMS5.7°æ±¾ÖдæÔÚÐÅϢй¶·ì϶¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý¶Ôinclude/downmix.inc.php»òinc/inc_archives_functions.phpÎļþ·¢ËͽÓÒªÇóÀûÓø÷ì϶»ñÈ¡ÆëÈ«õè¾¶¡£¡£¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Apache_Druid_LoadData_ËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2021-36749][CNNVD-202109-1676]

°²È«ÀàÐÍ£º

Îļþ¶ÁÈ¡

ÊÂÎñÃèÊö:

ApacheDruidÊÇÒ»¸öʵʱ³½ÎöÐÍÊý¾Ý¿â£¬£¬Ö¼ÔÚ¶Ô´óÐÍÊý¾Ý¼¯½øÐм±¾çµÄ²éÎÊ·ÖÎö¡£¡£¡£ÔÚApacheDruidϵͳÖУ¬£¬InputSourceÓÃÓÚ´Óij¸öÊý¾ÝÔ´¶ÁÈ¡Êý¾Ý¡£¡£¡£ÓÉÓÚûÓжÔÓû§¿É¿ØµÄHTTPInputSource×öÏÞ¶È£¬£¬ApacheDruidÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§ÒÔDruid·þÎñÆ÷¹ý³ÌµÄȨÏÞ´ÓÖ¸¶¨Êý¾ÝÔ´¶ÁÈ¡Êý¾Ý£¬£¬Ô̺¬±¾µØÎļþϵͳ¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý½«ÎļþURL´«µÝ¸øHTTPInputSourceÀ´ÈƹýÀûÓ÷¨Ê½¼¶´ËÍâÏÞ¶È¡£¡£¡£ÓÉÓÚApacheDruidĬÈÏÇé¿öϲ»×ãÊÚȨÈÏÖ¤£¬£¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâÒªÇ󣬣¬ÔÚδÊÚȨÇé¿öÏÂÀûÓø÷ì϶¶ÁÈ¡ËÁÒâÎļþ£¬£¬×îÖÕµ¼Ö·þÎñÆ÷Ãô¸ÐÐÅϢй¶¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_WordPress_δÊÚȨ½Ó¼û[CVE-2019-17671][CNNVD-201910-1180]

°²È«ÀàÐÍ£º

·ÇÊÚȨ½Ó¼û/ȨÏÞÈÆ¹ý

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃWordPress5.2.3ÒÔǰµÄ·ì϶£¬£¬½øÐÐδÊÚȨµÄ°ÂÃØÎļþ½Ó¼û

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ǰ̨ËÁÒâÓû§ÃÜÂëÅú¸Ä·ì϶

°²È«ÀàÐÍ£º

Âß¼­/Éè¼ÆÃýÎó

ÊÂÎñÃèÊö:

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£¡£¡£DedeCMSÔÚÓû§ÃÜÂëÖØÖÃÖ°ÄÜ´¦£¬£¬php´æÔÚÈõÀàÐͱÈÁ¦£¬£¬µ¼ÖÂÈôÊÇÓû§Ã»ÓÐÉèÖÃÃܱ£ÎÊÌâµÄÇé¿öÏ£¬£¬¹¥»÷ÕßÄܹ»ÈƹýÑéÖ¤Ãܱ£ÎÊÌ⣬£¬Ö±½ÓÅú¸ÄÃÜÂë(ÖÎÀíÔ±ÕË»§Ä¬Èϲ»ÉèÖÃÃܱ£ÎÊÌâ)¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ǰ̨ÎļþÉÏ´«·ì϶

°²È«ÀàÐÍ£º

ÎļþÉÏ´«

ÊÂÎñÃèÊö:

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£¡£¡£DedeCmsÔÚÓû§°ä²¼ÎÄÕÂÉÏ´«Í¼Æ¬´¦´æÔÚÎļþÉÏ´«·ì϶£¬£¬¸Ã·ì϶ԴÓÚ¶ÔÉÏ´«Îļþºó׺¼ì²â²»ÑϽ÷£¬£¬¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ½ÚÖÆÖ÷»ú¡£¡£¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Phpcms_install.php_ǰ̨Getshell

°²È«ÀàÐÍ£º

ÅäÖò»µ±/ÃýÎó

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ip¿ÉÄÜ´æÔÚÕýÔÚÀûÓÃÖ÷ÕÅipµÄPhpcmsÉÏδɾ³ýµÄinstall.php½øÐжñÒâ¹¥»÷µÄÐÐΪ£¬£¬Ä¿Ç°¹æ¶¨ÎÞ·¨ÕýÈ·ÅжÏÊÇ·ñΪ¶ñÒâ¹¥»÷¡£¡£¡£PHPCMSÊÇ¿ªÔ´µÄÕûվϵͳ¡£¡£¡£PHPCMS´æÔÚPHPCMS_v2008_preview.php×¢Èë·ì϶£¬£¬¹¥»÷ÕßÀûÓô˷ì϶ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬»ñÈ¡Êý¾Ý¿âºÍÖÎÀíԱȨÏÞ¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ADSelfService-PlusδÊÚȨ_ËÁÒâ´úÂëÖ´ÐÐ[CVE-2021-40539][CNNVD-202109-330]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

ZOHOManageEngineADSelfServicePlusÊÇÃÀ¹ú׿ºÀ£¨ZOHO£©¹«Ë¾µÄÕë¶ÔActiveDirectoryºÍÔÆÀûÓ÷¨Ê½µÄ¼¯³Éʽ×ÔÖ÷ÃÜÂëÖÎÀíºÍµ¥µãµÇ¼½â¾ö¹æ»®¡£¡£¡£ZohoManageEngineADSelfServicePlus6113°æ±¾¼°¸üÔç°æ±¾´æÔÚÊÚȨÎÊÌâ·ì϶£¬£¬¸Ã·ì϶ԴÓÚÈí¼þºÜÈÝÒ×ÈÆ¹ýRESTAPIÈÏÖ¤£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_Spring-api-actuatorÓйØÎļþ_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

SpringBoot¹Ù·½ÌṩÁËspring-boot-starter-actuator³¡¾°Æô¶¯Æ÷ÓÃÓÚϵͳµÄ¼à¿ØÖÎÀí£¬£¬Äܹ»Í¨¹ýHTTP£¬£¬JMX£¬£¬SSHºÍ̸À´½øÐвÙ×÷£¬£¬×Ô¶¯µÃµ½É󼯡¢¡¢½¡¿µ¼°Ö¸±êÐÅÏ¢µÈ¡£¡£¡£ÓйØÎļþ½ÔΪÃô¸ÐÎļþ£¬£¬Î´×ö½Ó¼ûȨÏÞ½ÚÖÆ½«µ¼ÖÂÐÅϢй¶¡£¡£¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_Swagger-api¹¤¾ß_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢¡¢»ùÓÚYAML¡¢¡¢JSON˵»°µÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£¡£¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£©£¬£¬ÓйØÎļþ¼Ð±»½Ó¼ûÓÐÐÅϢй¶·çÏÕ¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Seowon-Intech-SWC-9100-Routers_ºÅÁîÖ´ÐÐ[CVE-2013-7179][CNNVD-201402-022]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

SeowonIntechSWC-9100RoutersÊǺ«¹úÈðÔªÒóÌØ£¨SeowonIntech£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£¡£¡£SeowonIntechSWC-9100·ÓÉÆ÷ÖеÄcgi-bin/diagnostic.cgiÎļþÖеÄpingÖ°ÄÜÖдæÔÚÊäÈëÑéÖ¤·ì϶¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú¡®ping_ipaddr¡¯²ÎÊýÖеÄshellÔª×Ö·ûÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÖ÷ÓòÃû½âÎöÒªÇó7

°²È«ÀàÐÍ£º

ÍÚ¿óÈí¼þ

ÊÂÎñÃèÊö:

¼ì²âµ½¿ÉÒÉÍÚ¿óľÂíÊÔͼÏνÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£ÍÚ¿óľÂí³¢ÊÔÏÎ½Ó¿ó³Ø£¬£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬£¬¿÷ËðCPU×ÊÔ´¡£¡£¡£ÈôÊÇΪÓû§Õý³£½Ó¼û¿ó³ØÖ÷Ò³£¬£¬ÔòºöÂÔ¸ÃÊÂÎñ¡£¡£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_MicrosoftOffice_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-40444][CVE-2021-40444][CNNVD-202109-350]

°²È«ÀàÐÍ£º

ÎļþÏÂÔØ

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipµØµãµÄÖ÷»úÕýÔÚÀûÓÃCVE-2021-40444ÏÂÔØ¶ñÒⷨʽ£¬£¬ÊÂÎñ¼ì²âÏìÓ¦°üÌØµã¡£¡£¡£CVE-2021-40444ÊÇÒ»¸öÔÚ2021Äê9Ô±»±¬³öµÄÔÚÒ°ÀûÓõķì϶£¬£¬Óû§Ö»±ØÒªË«»÷Ö´ÐÐdocxÎļþ»òʹÓÃie½Ó¼û¶ñÒâÍøÕ¾£¬£¬¼´¿ÉÖ´ÐжñÒⷨʽ¡£¡£¡£¸Ã·ì϶λÓÚWindowsµÄMSHML×é¼þ£¬£¬MSHML×é¼þÊÇ΢ÈíIEä¯ÀÀÆ÷µÄÅŰæÒýÇæ£¬£¬Ò²Äܹ»ÔÚoffice·¨Ê½ÖгöÏÖwebÒ³Ãæ¡£¡£¡£MSHTMLÌṩÁËCOM½Ó¿Ú£¬£¬ÈκÎÖ§³ÖCOMµÄ»·¾³¶¼Äܹ»Í¨¹ý¸Ã×é¼þ½Ó¼û¡¢¡¢±à×ëÍøÒ³¡£¡£¡£

¸üй¦·ò£º

20211228


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£¡£¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£¡£¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£¡£

¸üй¦·ò£º

20211228