ÿÖÜÉý¼¶²¼¸æ-2022-12-27
°ä²¼¹¦·ò 2022-12-27
ÊÂÎñÃû³Æ£º£º | HTTP_ÌáȨ¹¥»÷_Cacti_ºÅÁîÖ´ÐÐ[CVE-2022-46169][CVE-2022-46169] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | CactiÏîÄ¿ÊÇÒ»¸ö¿ªÔ´Æ½Ì¨£¬£¬¿ÉΪÓû§Ìṩ׳´óÇÒ¿ÉÀ©´óµÄ²Ù×÷¼à¿ØºÍ¹ÊÕÏÖÎÀí¿ò¼Ü¡£¡£ÓÉÓÚremote_agent.phpÖеÄcasePOLLER_ACTION_SCRIPT_PHPÔÚʹÓÃproc_openº¯Êýʱδ¶Ô´«ÈëµÄpoller_id²ÎÊý×öÑϸñ¹ýÂË£¬£¬¹¥»÷Õ߿ɻú¹ØÂú×ãǰÌáµÄpayload¶ÔÓйØÖ¸±êϵͳ½øÐкÅÁî×¢È룬£¬µ¼ÖÂÔ¶³ÌºÅÁîÖ´ÐС£¡£Ó°ÏìÁìÓò£º£ºCacti==1.2.22 |
¸üй¦·ò£º£º | 20221227 |
ÊÂÎñÃû³Æ£º£º | TCP_ÌáȨ¹¥»÷_Hessain_lite_´úÂëÖ´ÐÐ[CVE-2022-39198] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | HessianÊÇÒ»ÖÖ¶¯Ì¬ÀàÐ͵Ķþ½øÖÆÐòÁл¯ºÍWeb·þÎñºÍ̸£¬£¬×¨ÎªÃæÏò¶ÔÏóµÄ´«Êä¶øÉè¼Æ¡£¡£Hessian-lite×î³õÊǹٷ½hessianµÄApachedubboembed°æ±¾£¬£¬Õâ¸öÄ£¿éºóÀ´´ÓDubboÖзÖÀë³öÀ´¡£¡£DubboµÄËùÓзÖÖ§£º£º2.5.x¡¢¡¢2.6.x(×Ô2.6.3)ºÍ2.7.x¶¼ÒÀÀµÓÚËü¡£¡£ÓÉÓÚHessian-liteÔÚ½øÐÐÐòÁл¯Êý¾Ý´«Êäʱ´æÔÚ·ì϶£¬£¬¹¥»÷Õß¿Éͨ¹ý¾«ÐĹ¹½¨µÄpayloadÈÆ¹ý¹Ù·½µÄºÚÃûµ¥ÀàÏÞ¶È£¬£¬´Ó¶øÔÚÖ¸±êÖ÷»úÉÏÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£ |
¸üй¦·ò£º£º | 20221227 |
ÊÂÎñÃû³Æ£º£º | HTTP_Îļþ²Ù×÷¹¥»÷_ThinkPhp_lang_pearcmd_ÎļþÔ̺¬[CVE-2022-47945] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃThinkphp¶à˵»°Ö°ÄÜÖдæÔÚµÄĿ¼´©Ô½½øÐÐÎļþÔ̺¬¹¥»÷¡£¡£ThinkPHPÊÇÒ»¸öÔÚÖйúʹÓý϶àµÄPHP¿ò¼Ü¡£¡£ÔÚÆä6.0.13°æ±¾¼°ÒÔǰ£¬£¬´æÔÚÒ»´¦±¾µØÎļþÔ̺¬·ì϶¡£¡£µ±¶à˵»°¸öÐÔ±»¿ªÆôʱ£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃlang²ÎÊýÀ´Ô̺¬ËÁÒâPHPÎļþ£¬£¬²¢½øÒ»²½Í¨¹ýpearcmd.phpʵÏÖËÁÒâÎļþдÈë¡£¡£ |
¸üй¦·ò£º£º | 20221227 |
ÊÂÎñÃû³Æ£º£º | HTTP_ÌáȨ¹¥»÷_fuelCMS_1.4.1_´úÂëÖ´ÐÐ[CVE-2018-16763] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | FUELCMSÊÇÒ»¿î»ùÓÚCodeIgniterµÄÄÚÈÝÖÎÀíϵͳ¡£¡£Æä1.4.1°æ±¾´æÔÚ·ì϶£¬£¬ÔÊÐíͨ¹ýpages/select/Ö´ÐÐphp´úÂ룬£¬Õâ¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£ |
¸üй¦·ò£º£º | 20221227 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º£º | HTTP_ÌáȨ¹¥»÷_DrayTek_Ô¤Éí·ÝÑéÖ¤_ºÅÁîÖ´ÐÐ[CVE-2020-8515] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½¹¥»÷ÕßÀûÓÃDrayTekÔ¤Éí·ÝÑéÖ¤´¦µÄÁ½´¦ºÅÁî×¢Èë·ì϶½øÐй¥»÷µÄÐÐΪ¡£¡£DrayTekÊÇÒ»¼ÒÔÚÖйú³ö²ú·À»ðǽ£¬£¬VPNÉ豸£¬£¬Â·ÓÉÆ÷£¬£¬WLANÉ豸µÈµÄÖÆ×÷ÉÌ¡£¡£¸Ã·ì϶ԴÓÚ/cgi-bin/mainfunction.cgi·¨Ê½Î´ÕýÈ·¹ýÂËkeyPath×ֶκÍrtick×Ö¶ÎÆäÖеÄÌØÊâ×Ö·û£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶²»¾¹ýÉí·ÝÑéÖ¤ÒÔrootȨÏÞÖ´ÐдúÂë¡£¡£¹¥»÷³É¹¦£¬£¬Äܹ»rootȨÏÞÖ´ÐдúÂë |
¸üй¦·ò£º£º | 20221227 |
ÊÂÎñÃû³Æ£º£º | TCP_Éó¼ÆÊÂÎñ_java.lang.ProcessBuilder_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´Ö¸±êIPÕýÔÚʹÓÃJava¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£ÔÚJavaÖУ¬£¬·¨Ê½¿ª·¢ÈËԱͨ³£»£»£»áͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½Ö´ÐÐÍⲿµÄShellºÅÁî¡£¡£ProcessBuilderÊÇjava5.0ÒýÈëµÄ£¬£¬start()²½Öè·µ»ØProcessµÄÒ»¸öʵÀý¡£¡£Í¨³£ÔÚJavaÓйصÄÀûÓÃϵͳÖУ¬£¬ÈôÊÇ´¦ÖÃÍⲿºÅÁîÖ´ÐÐʱ£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâ¸ö·ì϶Զ³Ì×¢ÈëºÅÁî»ò´úÂë²¢Ö´ÐС£¡£ÖîÈçStruts2¡¢¡¢SpringÕâЩÀûÓÃÒѾ±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬ÀýÈçOgnl±í°×ʽºÍSpEL±í°×ʽµÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¹¥»÷Õßͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½ÔÚ³öȱµãÀûÓÃÖÐÖ´ÐÐËÁÒâ´úÂë»òºÅÁ£¬½øÒ»²½ÆëÈ«½ÚÖÆÖ¸±ê·þÎñÆ÷¡£¡£³¢ÊÔÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£ |
¸üй¦·ò£º£º | 20221227 |
ÊÂÎñÃû³Æ£º£º | HTTP_Îļþ²Ù×÷¹¥»÷_ThinkPhp_lang_ÎļþÔ̺¬[CVE-2022-47945] |
°²È«ÀàÐÍ£º£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃThinkphp¶à˵»°Ö°ÄÜÖдæÔÚµÄĿ¼´©Ô½½øÐÐÎļþÔ̺¬¹¥»÷¡£¡£hinkPHPÊÇÒ»¸öÔÚÖйúʹÓý϶àµÄPHP¿ò¼Ü¡£¡£ÔÚÆä6.0.13°æ±¾¼°ÒÔǰ£¬£¬´æÔÚÒ»´¦±¾µØÎļþÔ̺¬·ì϶¡£¡£µ±¶à˵»°¸öÐÔ±»¿ªÆôʱ£¬£¬¹¥»÷ÕßÄܹ»Ê¹ÓÃlang²ÎÊýÀ´Ô̺¬ËÁÒâPHPÎļþ¡£¡£ |
¸üй¦·ò£º£º | 20221227 |


¾©¹«Íø°²±¸11010802024551ºÅ