ÿÖÜÉý¼¶²¼¸æ-2022-08-05

°ä²¼¹¦·ò 2022-08-05

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_GITEA_1.4.0_Îļþ¶ÁÈ¡

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

GiteaÊÇ´ÓgogsÑÜÉú³öµÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬£¬ÊÇÒ»¸öÀàËÆÓÚGithub¡¢¡¢¡¢GitlabµÄ¶àÓû§Git²Ö¿âÖÎÀíÆ½Ì¨¡£¡£¡£Æä1.4.0°æ±¾ÖÐÓÐÒ»´¦Âß¼­ÃýÎ󣬣¬µ¼ÖÂδÊÚȨÓû§Äܹ»´©Ô½Ä¿Â¼£¬£¬¶ÁдËÁÒâÎļþ£¬£¬×îÖÕµ¼ÖÂÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_ÌìÈÚÐÅ_ÉÏÍøÐÐΪÖÎÀíϵͳ_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÌìÈÚÐÅÉÏÍøÖÎÀíϵͳµÄ·ì϶½øÐÐËÁÒâºÅÁîÖ´ÐС£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_H3C_CVM_ËÁÒâÎļþÉÏ´«

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

H3CCVM(ÔÆÐé¹¹»¯ÖÎÀíϵͳ)´æÔÚÒ»¸öǰ̨ËÁÒâÎļþÉÏ´«·ì϶¡£¡£¡£ÓÉÓÚδ¶Ô´«²Î½øÐкϷ¨ÐÔУÑ飬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹ØÊý¾Ý°üÉÏ´«ËÁÒâÀàÐÍÎļþ¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_PbootCMS-parserIfLabel_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

PbootCMSÊÇÒ»¿î¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾¿ª·¢½¨ÉèÖÎÀíϵͳ¡£¡£¡£ÆäÖеÄparserIfLabel²½Öè´æÔÚÄ£°å×¢Èë·ì϶£¬£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶»ñȡָ±êÖ÷»úȨÏÞ¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_×¢Èë¹¥»÷_ºì·«Ò½ÁÆÔÆ_OA_SQL×¢Èë

°²È«ÀàÐÍ£º£º£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º£º£º

ÕÑͨºì·«¿Æ¼¼ÓÐÏÞ¹«Ë¾£¨ÒÔϼò³Æ£º£º£ººì·«¿Æ¼¼£©ÊÇÊ®ÐÛʦ¹¤¼¯ÍÅÖ®Ò»£¬£¬ÊÇÖйú´¬²°¼¯ÍÅÓÐÏÞ¹«Ë¾ÆìϹ㴬¹ú¼ÊÓÐÏÞ¹«Ë¾¿Ø¹ÉµÄ¸ßм¼ÊõÆóÒµ¡£¡£¡£º£º£ºì·«iOfficeÒ½Ôº°æ´æÔÚSQL×¢Èë·ì϶£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Êý¾Ý¿âÃô¸ÐÐÅÏ¢¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

OG¶«·½Ìü¡¤(Öйú´ó½)

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Roxy-WI-options.py_ºÅÁîÖ´ÐÐ[CVE-2022-31137][CNNVD-202207-676]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

Roxy-WIÊÇÓÃÓÚÖÎÀíHaproxy¡¢¡¢¡¢NginxºÍKeepalived·þÎñÆ÷µÄWeb½çÃæ¡£¡£¡£ÆäÖÐ6.1.1.0֮ǰµÄoptions.py´æÔÚ·ì϶£¬£¬¹¥»÷Õß¿ÉÄÜÔÚδÊÚȨµÄÇé¿öÏÂÖ´ÐÐËÁÒâºÅÁ£¬½ÚÖÆÏµÍ³È¨ÏÞ

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢E-office-do_excel.php_ÎļþдÈë

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£¡£¡£ÆäÖÐ/do_excel.php½Ó¿Ú´æÔÚ·ì϶£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶дÈë¶ñÒâÎļþ£¬£¬Ö²Èëwebshell£¬£¬»ñȡָ±êϵͳȨÏÞ¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_º£¿£¿£¿µÍþÊÓ×ÛºÏÔËÓªÖÎÀíÆ½Ì¨_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

º£¿£¿£¿µÍþÊÓ×ÛºÏÔËÓªÖÎÀíÆ½Ì¨Ô̺¬fastjson×é¼þ£¬£¬·¢ËͶñÒâjsonÊý¾ÝÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_ÁéͨOA_·ÇÊÚȨ½Ó¼û

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

ÁéͨOAÊÇÒ»Ìװ칫ϵͳ¡£¡£¡£ÓÉÓÚÁéͨOAÖÐheader.inc.php´æÔÚ·ì϶£¬£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýµÇ½ÏÞ¶È£¬£¬µ¼ÖÂδÊÚȨ½Ó¼û¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_Struts2_S2-061Ô¶³ÌºÅÁîÖ´Ðй¥»÷[CVE-2020-17530/CVE-2021-31805][CNNVD-202012-449/CNNVD-202204-3223]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄÒªÇ󣬣¬Òý·¢OGNL±í°×ʽ½âÎö£¬£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Laravel_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2021-3129]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

LaravelÊÇÒ»Ì×¼ò½à¡¢¡¢¡¢¿ªÔ´µÄPHPWeb¿ª·¢¿ò¼Ü£¬£¬Ö¼ÔÚʵÏÖWebÈí¼þµÄMVC¼Ü¹¹¡£¡£¡£µ±Laravel¿ªÆôÁËDebugģʽʱ£¬£¬ÓÉÓÚLaravel×Ô´øµÄIgnition×é¼þ¶Ôfile_get_contents()ºÍfile_put_contents()º¯ÊýµÄ²»°²È«Ê¹Ó㬣¬¹¥»÷ÕßÄܹ»Í¨¹ýÌáÒé¶ñÒâÒªÇ󣬣¬»ú¹Ø¶ñÒâLogÎļþ´¥·¢Phar·´ÐòÁл¯£¬£¬×îÖÕÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Seowon-Intech-SWC-9100-Routers_Ô¶³ÌºÅÁîÖ´ÐÐ[CVE-2013-7179][CNNVD-201402-022]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

SeowonIntechSWC-9100RoutersÊǺ«¹úÈðÔªÒóÌØ£¨SeowonIntech£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£¡£¡£SeowonIntechSWC-9100·ÓÉÆ÷ÖеÄcgi-bin/diagnostic.cgiÎļþÖеÄpingÖ°ÄÜÖдæÔÚÊäÈëÑéÖ¤·ì϶¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú¡®ping_ipaddr¡¯²ÎÊýÖеÄshellÔª×Ö·ûÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£¡£¡£

¸üй¦·ò£º£º£º

20220805

 

ÊÂÎñÃû³Æ£º£º£º

TCP_ÍÚ¿óľÂí_CoinMiner_ÃÅÂÞ±ÒJSON-RPCºÍ̸_ÍÚ¿ó½ÚÖÆºÅÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý2(XMR)

°²È«ÀàÐÍ£º£º£º

È䳿²¡¶¾

ÊÂÎñÃèÊö£º£º£º

¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCºÍ̸ÒÉËÆÅ²ÓÃÁËÃÅÂÞ±ÒÍÚ¿óAPIº¯Êý¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿ç˵»°Ô¶³ÌŲÓúÍ̸¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¬£¬±ãÓÚµ÷ÊÔÀ©´óµÄÌØµã¡£¡£¡£Ëü¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏàÓ¦µÄ´¦Öù涨,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÌåʽ£¬£¬¹æ·¶×ÔÉíÊÇ´«ÊäÎ޹صÄ£¬£¬Äܹ»ÓÃÓÚ¹ý³ÌÄÚͨѶ¡¢¡¢¡¢socketÌ×½Ó×Ö¡¢¡¢¡¢HTTP»ò¸÷ÀàÐÂÎÅͨѶ»·¾³¡£¡£¡£ÃÅÂÞ±ÒÀûÓÿª·¢½Ó¿ÚѡȡJSON-PRC³ß¶È£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹صÄ£¬£¬Äܹ»Ê¹ÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëÍÚ¿ó½Úµã½»»¥¡£¡£¡£ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´½øÐÐÍڿ󡣡£¡£

¸üй¦·ò£º£º£º

20220805


 

ÊÂÎñÃû³Æ£º£º£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌºÅÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡¢¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâOGNL±í°×ʽ¡£¡£¡£·ì϶´æÔڵİ汾£º£º£ºS2-016£º£º£ºStruts2.0.0-Struts2.3.15S2-017£º£º£ºStruts2.0.0-Struts2.3.15S2-018£º£º£ºStruts2.0.0-Struts2.3.15.2¹¥»÷³É¹¦£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£

¸üй¦·ò£º£º£º

20220805