ÿÖÜÉý¼¶²¼¸æ-2023-01-10

°ä²¼¹¦·ò 2023-01-10
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º £º

HTTP_Îļþ²Ù×÷¹¥»÷_Lucee_Admin_imgProcess.cfm_ËÁÒâÎļþдÈë[CVE-2021-21307]

°²È«ÀàÐÍ£º£º £º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º £º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃLuceeAdminÖеÄËÁÒâÎļþдÈë·ì϶¡£¡£¡£¡£LuceeServerÊÇÒ»ÖÖ¶¯Ì¬µÄ¡¢¡¢¡¢»ùÓÚJava(JSR-223)µÄÏóÕ÷ºÍ¾ç±¾Ëµ»°£¬£¬£¬ÓÃÓÚ¼±¾çWebÀûÓ÷¨Ê½¿ª·¢¡£¡£¡£¡£ÔÚ°æ±¾5.3.7.47¡¢¡¢¡¢5.3.6.68»ò5.3.5.96֮ǰµÄLuceeAdminÖдæÔÚδ¾­Éí·ÝÑéÖ¤µÄËÁÒâÎļþдÈë·ì϶¡£¡£¡£¡£

¸üй¦·ò£º£º £º

20230110

 

ÊÂÎñÃû³Æ£º£º £º

HTTP_Îļþ²Ù×÷¹¥»÷_WeiPHP_5.0_Îļþ¶ÁÈ¡[CNVD-2020-68596]

°²È«ÀàÐÍ£º£º £º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º £º

¼ì²âµ½Ô´ipÖ÷»ú£¬£¬£¬ÕýÔÚÀûÓÃWeiphp5.0ǰ̨ÎļþËÁÒâ¶ÁÈ¡·ì϶½øÐй¥»÷£¬£¬£¬¶ÁÈ¡Êý¾Ý¿âÅäÖõÈÃô¸ÐÎļþ¡£¡£¡£¡£

¸üй¦·ò£º£º £º

20230110

 

ÊÂÎñÃû³Æ£º£º £º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-001/S2-002_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º £º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º £º

Struts2ÊÇÒ»¸ö»ùÓÚMVCÉè¼ÆÄ£Ê½µÄWebÀûÓÿò¼Ü£¬£¬£¬¸Ã·ì϶ÓÉÓÚÓû§Ìá½»±íµ¥Êý¾Ý²¢ÇÒÑé֤ʧ°Üʱ£¬£¬£¬ºó¶Ë»á½«Óû§Ö®Ç°Ìá½»µÄ²ÎÊýֵʹÓÃOGNL±í°×ʽ%{value}½øÐнâÎö£¬£¬£¬¶øºóÖØÐÂÌî³äµ½¶ÔÓ¦µÄ±íµ¥Êý¾ÝÖС£¡£¡£¡£ÀýÈç×¢²á»òµÇÂ¼Ò³Ãæ£¬£¬£¬Ìύʧ°Üºó¶Ëͨ³£»áĬÈÏ·µ»ØÖ®Ç°Ìá½»µÄÊý¾Ý£¬£¬£¬ÓÉÓÚºó¶ËʹÓÃ%{value}¶ÔÌá½»µÄÊý¾ÝÖ´ÐÐÁËÒ»´ÎOGNL±í°×ʽ½âÎö£¬£¬£¬ËùÒÔÄܹ»Ö±½Ó»ú¹ØPayload½øÐкÅÁîÖ´ÐС£¡£¡£¡£

¸üй¦·ò£º£º £º

20230110