ÿÖÜÉý¼¶²¼¸æ-2022-08-09

°ä²¼¹¦·ò 2022-08-09
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º

HTTP_Microsoft-Exchange-SERVER_·þÎñÆ÷¶ËÒªÇóαÔì[CVE-2021-26855]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

µ±Ç°Ö÷»úÕýÔÚÔâ·êMicrosoft-Exchange-SERVER_·þÎñÆ÷¶ËÒªÇóαÔì¹¥»÷

¸üй¦·ò£º£º

20220809

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º

TCP_ľÂíºóÃÅ_vbs_webshell_Ò»¾ä»°Ä¾Âí

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÖ÷ÕÅÖ÷»úÉÏ´«VBSÒ»¾ä»°Ä¾ÂíµÄÐÐΪ¹¥»÷Õß³¢ÊÔÏò·þÎñÆ÷ÉÏ´«VBSÒ»¾ä»°Ä¾ÂíÎļþ£¬£¬ÈôÊÇÉÏ´«³É¹¦½«Í¨¹ýÒ»¾ä»°Ä¾ÂíÏνӹ¤¾ß¶Ô·þÎñÆ÷½øÐнÚÖÆ¡£¡£³¢ÊÔÉÏ´«Webshell£¬£¬»ñÈ¡ÍøÕ¾½ÚÖÆÈ¨¡£¡£

¸üй¦·ò£º£º

20220809

 

ÊÂÎñÃû³Æ£º£º

HTTP_ÌáȨ¹¥»÷_Apache-Spark-doAS_ºÅÁî×¢Èë[CVE-2022-33891]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

ApacheSparkUIͨ¹ýÅäÖÃÑ¡Ïîspark.acls.enableÉí·ÝÑéÖ¤¹ýÂËÆ÷£¬£¬²é³­Óû§ÊÇ·ñÓµÓв鿴»òÅú¸ÄÀûÓᣡ£ÈôÊÇÆôÓÃÁËACL£¬£¬ÔòHttpSecurityFilterÖеĴúÂëÔÊÐíijÈËͨ¹ýÌṩËÁÒâÓû§ÃûÀ´Ö´ÐзÂÕÕ¡£¡£¶ñÒâÓû§¿ÉÄÜÈÆ¹ýȨÏ޲鳭ְÄÜ£¬£¬ÊäÈë¹¹½¨Ò»¸öUnixshellºÅÁ£¬²¢ÇÒÖ´ÐÐËü¡£¡£½«µ¼ÖÂÖ´ÐÐËÁÒâshellºÅÁî¡£¡£

¸üй¦·ò£º£º

20220809

 

ÊÂÎñÃû³Æ£º£º

HTTP_ÌáȨ¹¥»÷_Master-IP-CAM-01_ºÅÁîÖ´ÐÐ[CVE-2019-8387]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

MasterIPCAM01ÊÇÒ»¿îÍøÂçÉãÏñ»ú¡£¡£MasterIPCAM013.3.4.2103°æ±¾ÖдæÔÚºÅÁî×¢Èë·ì϶¡£¡£¸Ã·ì϶ԴÓÚÍⲿÊäÈëÊý¾Ý»ú¹Ø¿ÉÖ´ÐкÅÁî¹ý³ÌÖУ¬£¬ÍøÂçϵͳ»ò²úƷδÕýÈ·¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨ºÅÁî¡£¡£

¸üй¦·ò£º£º

20220809

 

ÊÂÎñÃû³Æ£º£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.3.2ÒÔÏÂ_ȨÏÞÈÆ¹ý[CVE-2016-6802][CNNVD-201609-372]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

ApacheShiroÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬£¬ËüÄܹ»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£Ä¿Ç°³£¼û¼¯³ÉÓÚ¸÷ÀàÀûÓÃÖнøÐÐÉí·ÝÑéÖ¤£¬£¬ÊÚȨµÈ¡£¡£¶ÔÓÚApacheShiro1.3.2֮ǰµÄ°æ±¾£¬£¬Ê¹ÓÃÒÔ/xx/../¿ªÍ·µÄurlÄܹ»ÈƹýshiroµÄÉí·ÝÑéÖ¤

¸üй¦·ò£º£º

20220809

 

ÊÂÎñÃû³Æ£º£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌºÅÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâOGNL±í°×ʽ¡£¡£·ì϶´æÔڵİ汾£º£ºS2-016£º£ºStruts2.0.0-Struts2.3.15S2-017£º£ºStruts2.0.0-Struts2.3.15S2-018£º£ºStruts2.0.0-Struts2.3.15.2¹¥»÷³É¹¦£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£

¸üй¦·ò£º£º

20220809