ÿÖÜÉý¼¶²¼¸æ-2022-10-04
°ä²¼¹¦·ò 2022-10-04ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_VMware_vCenter_Server_SSRF·þÎñ¶ËÒªÇóαÔì[CVE-2021-21973][CNNVD-202102-1559] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃVMwarevCenterServerδ¶ÔÓû§ÌṩµÄÊäÈëÑéÖ¤µÄ·ì϶£¬£¬£¬ÔÚ¡°vcIP¡±»ú¹Ø¶ñÒâip£¬£¬£¬ºýŪÀûÓ÷¨Ê½ÏòËÁÒâϵͳÌáÒéÒªÇóʵÏÖÄÚÍøÉ¨Ã裬£¬£¬´Ó¶ø»ñÈ¡ÄÚÍøÐÅÏ¢£¬£¬£¬µ¼ÖÂÐÅϢй¶¡£¡£¡£VMwarevCenterServer£¨ÒÔǰ³ÆÎªVMwareVirtualCenter£©£¬£¬£¬¿É¼¯ÖÐÖÎÀíVMwarevSphere»·¾³£¬£¬£¬ÓëÆäËûÖÎÀíÆ½Ì¨Ïà±È£¬£¬£¬¼«´óµØÌá¸ßÁËITÖÎÀíÔ±¶ÔÐé¹¹»·¾³µÄ½ÚÖÆ¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ToTolink_t6_firmware_ºÅÁîÖ´ÐÐ[CVE-2022-38828] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃToTolink_t6_firmwareV4.1.5cu.709_B20210518ÖÐcstecgi.cgi´¦µÄ·ì϶£¬£¬£¬»ú¹Ø¶ñÒâºÅÁî½øÐкÅÁî×¢Èë¹¥»÷£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_RDP_ɨÃè |
°²È«ÀàÐÍ£º | °²È«É¨Ãè |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓöÔÖ÷ÕÅÖ÷»úʹÓÃNMAPͨ¹ýRDPºÍ̸»ñÈ¡ÍÆËã»úÐÅÏ¢µÄÐÐΪ¡£¡£¡£¿£¿ÉÄܻᵼÖÂϵͳй¶ÓйØÐÅÏ¢¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_RDP_ɨÃè |
°²È«ÀàÐÍ£º | °²È«É¨Ãè |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓöÔÖ÷ÕÅÖ÷»úʹÓÃNMAPͨ¹ýSMBºÍ̸»ñÈ¡ÍÆËã»úÐÅÏ¢µÄÐÐΪ¡£¡£¡£¿£¿ÉÄܻᵼÖÂϵͳй¶ÓйØÐÅÏ¢¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ThinkPHP5.15.2_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP5Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ£¬£¬£¬¸Ã·ì϶ÊÇÓÉÓÚThinkPHP5¿ò¼Üµ×²ã¶Ô½ÚÖÆÆ÷Ãû¹ýÂ˲»ÑÏ£¬£¬£¬´Ó¶øÈù¥»÷ÕßÄܹ»Í¨¹ýurlŲÓõ½ThinkPHP¿ò¼ÜÄÚ²¿µÄÃô¸Ðº¯Êý£¬£¬£¬½ø¶øµ¼ÖÂgetshell·ì϶¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ThinkPHPÊÇÒ»¸ö¼±¾ç¡¢¡¢¼æÈݲ¢ÇÒµ¥Ò»µÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Jolokia_JNDI_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃJolokiaµÄJNDI½Ó¿Ú»ú¹Ø¶ñÒâldapºÍrmiÒªÇ󣬣¬£¬´Ó¶øÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£JolokiaÊÇÒ»¸öJMX-HTTPÏÎ½ÓÆ÷£¬£¬£¬Äܹ»´úÌæJSR-160ÏÎ½ÓÆ÷¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ThinkPHP5.0.x_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2018-20062][CNNVD-201812-489] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP¿ò¼ÜµÄÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ£¬£¬£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬£¬£¬ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£¡£¡£ThinkPHPÊÇÒ»¸öÊ¢ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_Social_Warfare_Plugin_before3.5.3_ÎļþÔ̺¬ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWordPressµÄSocial_Warfare²å¼þ½øÐÐÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬¸Ã²å¼þûÓжԴ«Èë²ÎÊý½øÐÐÑϸñ½ÚÖÆÒÔ¼°¹ýÂË£¬£¬£¬µ¼Ö¹¥»÷Õ߿ɻú¹Ø¶ñÒâpayload£¬£¬£¬ÎÞÐèºó¶ÜȨÏÞ£¬£¬£¬Ö±½ÓÔì³ÉÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¡£¡£social-warfareÊÇÒ»¿îWordPressÉç½»·ÖÏí°´Å¥²å¼þ¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON_databind_caucho_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬£¬£¬Í¨¹ýcom.caucho.config.types.ResourceRefÀà»ú¹Ø¶ñÒâjava´úÂë¡£¡£¡£jackson-databindÊÇ´ÓÊôFasterXMLÏîÄ¿×éϵÄJSON´¦Öÿ⡣¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON_Shiro_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬£¬£¬Í¨¹ýshiro-coreÀà´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ²Ù×÷¡£¡£¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄÖ÷Ìâ×é¼þÖ®Ò»¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_WebLogic_´úÂëÖ´ÐÐ[CVE-2022-21350] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWeblogicÖеÄOracleFusionMiddleware£¨×é¼þ£ºCore£©Öеķì϶»ú¹Ø¶ñÒâ·´ÐòÁдúÂëͨ¹ýT3½Ó¼ûÍøÂçÀ´½øÐй¥»÷£»£»WeblogicÊÇĿǰȫÇòÊг¡ÉÏÀûÓÃ×î¿í·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÀûÓ÷¨Ê½·þÎñÆ÷£¬£¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÀûÓ÷¨Ê½£¬£¬£¬Ö§³ÖÐÂÖ°ÄÜ£¬£¬£¬¿É½µµÍÔËÓª³É±¾£¬£¬£¬Ìá¸ß»úÄÜ£¬£¬£¬¼ÓÇ¿¿ÉÀ©´óÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£T3ºÍ̸ÊÇÓÃÓÚWeblogic·þÎñÆ÷ºÍÆäËûJavaApplicationÖ®¼ä´«ÊäÐÅÏ¢µÄºÍ̸£¬£¬£¬ÊÇʵÏÖRMIÔ¶³Ì¹ý³ÌŲÓõÄרÓкÍ̸£¬£¬£¬ÆäÔÊÐí¿Í»§¶Ë½øÐÐJNDIŲÓᣡ£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÍøÂçɨÃè_Ìì¾µ6.0ɨÃèÆ÷ |
°²È«ÀàÐÍ£º | °²È«É¨Ãè |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·µÄÖ÷»úÕýÔÚʹÓÃÌì¾µ6.0ɨÃ蹤¾ß¶ÔÖ÷ÕÅIPµØÖ·½øÐзì϶ɨÃè¡£¡£¡£Ìì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳÊÇOG¶«·½Ìü¹«Ë¾×ÔÖ÷Ñз¢µÄ»ùÓÚÍøÂçµÄ°²È«»úÄÜÆÀ¹À·ÖÎöϵͳ£¬£¬£¬Äܹ»¶ÔÍøÂçÖеĸ÷Ààϵͳ¡¢¡¢É豸ºÍÊý¾Ý¿â½øÐзì϶ɨÃ裬£¬£¬¶ÔÍøÂç½øÐÐÓÐЧµÄÆÀ¹À£¬£¬£¬²¢Ìá³ö½¨ÉèÐԵĽâ¾ö¹æ»®¡£¡£¡£¿£¿ÉÄܻᵼÖÂÖ÷ÕÅϵͳй¶ijЩÃô¸ÐÐÅÏ¢¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_×¢Èë¹¥»÷_WebLogic_Blind_XXE×¢Èë[CVE-2019-2647] |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWebLogic_Blind_XXE×¢Èë·ì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£WebLogic_Blind_XXE×¢Èë·ì϶£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3ºÍ̸ÖУ¬£¬£¬Í¨¹ý¶ÔT3ºÍ̸ÖеÄpayload½øÐз´ÐòÁл¯£¬£¬£¬´Ó¶øÊµÏÖ¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlindXXE¹¥»÷£¬£¬£¬¶Áȡָ±êϵͳÎļþ¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Adobe_Coldfusion_JNBridge_listener_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2019-7839][CNNVD-201906-514] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÕýÔÚÀûÓÃAdobeColdfusionµÄJNBridge×é¼þµÄ·ì϶»ú¹Ø¶ñÒâjava´úÂ룬£¬£¬´Ó¶øÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£AdobeColdFusionÊÇÒ»¸öÉÌÓõļ±¾ç¿ª·¢Æ½Ì¨¡£¡£¡£ËüÄܹ»×÷Ϊһ¸ö¿ª·¢Æ½Ì¨Ê¹Ó㬣¬£¬Ò²Äܹ»ÌṩFlashÔ¶³Ì·þÎñ»òÕß×÷ΪAdobeFlexÀûÓõĺó¶Ü·þÎñÆ÷¡£¡£¡£ÓÉÓÚJNBridge×é¼þ´æÔÚȱµã£¬£¬£¬¶øColdFusionĬÈÏ¿ªÆôJNBridge×é¼þ£¬£¬£¬¿ÉÄܵ¼Ö´úÂëÖ´Ðзì϶¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Cacti_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-8813][CNNVD-202002-1075] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚͨ¹ýÔÚCacti1.2.8¼°Ö®Ç°µÄ°æ±¾µÄ·Ã¿ÍÒ³Ãæ¡°graph_realtime.php¡±´¦Î´¶ÔCookie´¦µÄÊäÈë½øÐÐÑéÖ¤µÄ·ì϶£¬£¬£¬»ú¹Ø¶ñÒâ´úÂë´Ó¶øÖ´ÐÐÔ¶³ÌºÅÁî¡£¡£¡££¬£¬£¬CactiÊÇÒ»Ì×»ùÓÚPHP,MySQL,SNMP¼°RRDTool¿ª·¢µÄÍøÂçÁ÷Á¿¼à²âͼÐηÖÎö¹¤¾ß¡£¡£¡£Ëüͨ¹ýsnmpgetÀ´»ñÈ¡Êý¾Ý£¬£¬£¬Ê¹ÓÃRRDtool»æ»Í¼ÐΣ¬£¬£¬²¢ÇÒÆëÈ«Äܹ»²»±ØÒªÏàʶRRDtool¸´ÔӵIJÎÊý¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Jellyfin_SSRF_·þÎñ¶ËÒªÇóαÔì[CVE-2021-29490] |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´Ö÷»úipÕýÔÚÀûÓÃJellyfin¼°10.7.3֮ǰµÄSSRF·ì϶£¬£¬£¬»ú¹Ø¶ñÒâÒªÇó¸Ã·ì϶̽²âÄÚÍøÐÅÏ¢¡£¡£¡£JellyfinÊÇÒ»¸öÃâ·ÑµÄÈí¼þýÌåϵͳ¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_weblogic_·þÎñ¶ËÒªÇóαÔì[CVE-2014-4210] |
°²È«ÀàÐÍ£º | °²È«É¨Ãè |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃweblogic·þÎñ¶ËÒªÇóαÔì·ì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£OracleWebLogicServerÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»¿îºÏÓÃÓÚÔÆ»·¾³ºÍ´«Í³»·¾³µÄÀûÓ÷þÎñÆ÷£¬£¬£¬ËüÌṩÁËÒ»¸öÏÖ´úÇáÐÍ¿ª·¢Æ½Ì¨£¬£¬£¬Ö§³ÖÀûÓôӿª·¢µ½³ö²úµÄÕû¸öÐÔÃüÖÜÆÚÖÎÀí£¬£¬£¬²¢¼ò»¯ÁËÀûÓõIJ¿ÊðºÍÖÎÀí¡£¡£¡£OracleFusionMiddleware10.0.2.0ºÍ10.3.6.0°æ±¾µÄOracleWebLogicServer×é¼þÖеÄWLS-WebServices×Ó×é¼þ´æÔÚ°²È«·ì϶¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶¶ÁÈ¡Êý¾Ý£¬£¬£¬Ó°ÏìÊý¾ÝµÄ±£ÃÜÐÔ¡£¡£¡£»£»ñÈ¡ÄÚÍøÐÅÏ¢¡£¡£¡£ |
¸üй¦·ò£º | 20221004 |


¾©¹«Íø°²±¸11010802024551ºÅ