ÿÖÜÉý¼¶Í¨¸æ-2021-09-21
Ðû²¼Ê±¼ä 2021-09-22ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÎļþ»á¼û_³£¼ûÃüÃû |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé»á¼ûÄ¿µÄIPÖ÷»úÉϵĿÉÒÉÎļþµÄÐÐΪ¡£´ËÊÂÎñ½ö¹©ÐÅÏ¢²Î¿¼£¬²»´ú±íÕæʵ¹¥»÷¡£ÐèҪȷÈÏ»á¼ûµÄÎļþÔÚÄ¿µÄIPÖ÷»úÉÏÊÇ·ñÕæʵ±£´æ¡£ÇÒÐèҪȷÈÏÎļþÄÚÈÝÊÇ·ñΪ¶ñÒâÄÚÈÝ¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_TP-Link_TL-WR940N_´úÂëÖ´ÐÐ[CVE-2019-6989][CNNVD-201904-442] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | TP-LinkTL-WR940NºÍTP-LinkTL-WR941ND¶¼ÊÇÖйúÆÕÁª£¨TP-Link£©µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£TP-LINKTL-WR940NºÍTL-WR941NDÖб£´æ»º³åÇø¹ýʧÎó²î¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏߣ¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æλÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_Gh0st_Shine_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø³ÌÐò£¬¹¦Ð§Ê®·ÖÇ¿Ê¢¡£¾ßÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢½¨É衢ɾ³ý£©¡¢Àú³ÌÖÎÀí¡¢ÏµÍ³·þÎñ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖնˡ¢ÆÁÄ»¼à¿Ø¡¢Éó²éÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Ç徲ɨÃè_ɨÃèÆ÷nessus |
Çå¾²ÀàÐÍ£º | Ç徲ɨÃè |
ÊÂÎñÐÎò£º | NessusÊÇÊ®·ÖÇ¿Ê¢µÄÎó²îɨÃèÆ÷£¬¸Ã¹¤¾ß°üÀ¨×îеÄÎó²îÊý¾Ý¿â£¬¼ì²âËÙÂʿ죬׼ȷÐԸߣ¬ÊÇÉø͸²âÊÔÖ÷Òª¹¤¾ßÖ®Ò»¡£¸Ã¸æ¾¯ËµÃ÷¼ì²âµ½nessusɨÃèÆ÷ɨÃèÁ÷Á¿¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Optergy-Proton-Enterprise_ÏÂÁî×¢ÈëÎó²î[CVE-2019-7276][CNNVD-201906-284] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | OptergyProtonEnterpriseÊÇÃÀ¹úOptergy¹«Ë¾µÄÒ»Ì×ÆóÒµÐÞ½¨ÖÎÀíϵͳ¡£OptergyProtonEnterprise2.3.0a¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ±½Óµ¼º½µ½Î´±»¼Í¼µÄºóÞ籾£¬»ñÈ¡ËùÓеÄϵͳ»á¼ûȨÏÞ£¬½ø¶øÒÔ×î¸ßȨÏÞÖ´ÐдúÂë¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_rConfig_System_ajaxArchiveFiles.phpÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-19509][CNNVD-202001-144] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃrConfig_System_ajaxArchiveFiles.phpÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£rConfig3.9.3Öз¢Ã÷ÁËÒ»¸öÎÊÌâ¡£Ô¶³ÌÈÏÖ¤Óû§¿ÉÒÔͨ¹ýÏòajaxArchiveFiles.php·¢ËÍGETÇëÇóÖ±½ÓÖ´ÐÐϵͳÏÂÁÓÉÓÚpath²ÎÊýûÓйýÂ˾Íת´ï¸øexecº¯Êý£¬Õâ»áµ¼ÖÂÏÂÁîÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_D-Link-DIR-818LW&DIR-822_ÏÂÁî×¢Èë[CVE-2018-19986][CNNVD-201905-305] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | D-LinkDIR-822ºÍD-LinkDIR-818LW¶¼ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£D-LinkDIR-818LWRev.A2.05.B03ºÍDIR-822B1202KRb06Öеġ®RemotePort¡¯²ÎÊý±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÏÂÁîµÈ¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨²Ù×÷ϵͳÏÂÁî¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Ãô¸ÐÎļþ»á¼û |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÄ¿µÄipÖ÷»úÖпÉÄÜ̻¶ÔÚÍâµÄÃô¸ÐÎļþ¡£ |
¸üÐÂʱ¼ä£º | 20210914 |
ÊÂÎñÃû³Æ£º | TCP_Java¶¯Ì¬Å²ÓÃ_java.lang.ProcessBuilder_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£ÔÚJavaÖУ¬³ÌÐò¿ª·¢Ö°Ô±Í¨³£»áͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨Ö´ÐÐÍⲿµÄShellÏÂÁî¡£ProcessBuilderÊÇjava5.0ÒýÈëµÄ£¬start()ÒªÁì·µ»ØProcessµÄÒ»¸öʵÀý¡£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬ÈôÊÇ´¦Öóͷ£ÍâÊÖÏÂÁîÖ´ÐÐʱ£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐÓõĹýÂË£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎó²îÔ¶³Ì×¢ÈëÏÂÁî»ò´úÂë²¢Ö´ÐС£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÒ»¾±»Åû¶³ö±£´æJavaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õßͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐí§Òâ´úÂë»òÏÂÁ½øÒ»²½ÍêÈ«¿ØÖÆÄ¿µÄ·þÎñÆ÷¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20210914 |
ÊÂÎñÃû³Æ£º | TCP_Java¾²Ì¬Å²ÓÃ_java.lang.Runtime_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£ÔÚJavaÖУ¬³ÌÐò¿ª·¢Ö°Ô±Í¨³£»áͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨Ö´ÐÐÍⲿµÄShellÏÂÁî¡£RuntimeÀàÊÇJava³ÌÐòµÄÔËÐÐʱÇéÐΣ¬¿ª·¢Õß¿ÉÒÔͨ¹ýgetRuntime()ÒªÁì»ñÈ¡Ä¿½ñRuntimeÔËÐÐʱ¹¤¾ßµÄÒýÓá£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬ÈôÊÇ´¦Öóͷ£ÍâÊÖÏÂÁîÖ´ÐÐʱ£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐÓõĹýÂË£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎó²îÔ¶³Ì×¢ÈëÏÂÁî»ò´úÂë²¢Ö´ÐС£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÒ»¾±»Åû¶³ö±£´æJavaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õßͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐí§Òâ´úÂë»òÏÂÁ½øÒ»²½ÍêÈ«¿ØÖÆÄ¿µÄ·þÎñÆ÷¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20210921 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_ÓÃÓÑNC_ÀúÊ·Îó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP¿ÉÄÜÕýÔÚʹÓÃÓÃÓÑNCµÄÎó²î¾ÙÐй¥»÷£»¹¥»÷Õßͨ¹ý½á¹¹ÓÃÓÑÌض¨µÄ·ÓÉʵÏÖ´úÂëÖ´ÐС¢Îļþ¶ÁÈ¡µÈ²Ù×÷£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳ¡£ |
¸üÐÂʱ¼ä£º | 20210921 |