ÿÖÜÉý¼¶Í¨¸æ-2021-10-26

Ðû²¼Ê±¼ä 2021-10-27

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁî×¢Èë[CVE-2017-7876][CNNVD-201704-779]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

QNAPSystemsQNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.6build20170517֮ǰµÄ°æ±¾Öб£´æÏÂÁî×¢ÈëÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î×¢ÈëÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_VMware_vCenter_Server_·þÎñÆ÷¶ËÇëÇóαÔìÎó²î[CVE-2021-21973][CNNVD-202102-1559]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃVMwarevCenterServer·þÎñÆ÷¶ËÇëÇóαÔìÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¸ÃÎó²îÔ´ÓÚVMwarevCenterServer²å¼þÖжÔÓû§ÌṩµÄÊäÈëÑéÖ¤²»µ±£¬Î´¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖƵÄHTTPÇëÇó£¬ÓÕÆ­Ó¦ÓóÌÐòÏòí§ÒâϵͳÌᳫÇëÇóʵÏÖÄÚÍøɨÃ裬»ñÈ¡ÄÚÍøÐÅÏ¢£¬µ¼ÖÂÐÅϢй¶¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jetty_WEB-INF_ÐÅϢй¶Îó²î[CVE-2021-34429]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

EclipseJetty°æ±¾9.4.37-9.4.42¡¢10.0.1-10.0.5ºÍ11.0.1-11.0.5£¬¿ÉÒÔʹÓÃһЩ±àÂë×Ö·û½á¹¹ÌØÊâµÄURIÀ´»á¼ûWEB-INFĿ¼µÄÄÚÈÝ¡£

¸üÐÂʱ¼ä£º

20211019

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-LinkDSL-2640U&DSL-2540U_ÏÂÁîÖ´ÐÐ[CVE-2018-5371][CNNVD-201801-545]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

D-LinkDSL-2640U×°±¸£¨¹Ì¼þΪIM_1.00ºÍME_1.00£©ºÍDSL-2540U×°±¸£¨¹Ì¼þΪME_1.00£©ÉϵÄdiag_ping.cmdÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýHTTPGETÇëÇóµÄipaddr×Ö¶ÎÖеÄshellÔª×Ö·ûÖ´ÐÐí§ÒâOSÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Subrion-CMS_´úÂëÖ´ÐÐ[CVE-2018-19422][CNNVD-201811-628]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SubrionCMSÊÇSubrionÍŶӿª·¢µÄÒ»Ì×»ùÓÚPHPµÄÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¸Ãϵͳ¿É±»¼¯³Éµ½ÍøÕ¾£¬²¢Ö§³Ö¶àÖÖÀ©Õ¹²å¼þµÈ¡£SubrionCMS4.2.1°æ±¾ÖеÄ/panel/uploads±£´æÇå¾²Îó²î£¬¸ÃÎó²îÔ´ÓÚ.htaccessÎļþûÓÐեȡ¶ÔphtºÍpharÎļþµÄÖ´ÐвÙ×÷¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú.pht»ò.pharÎļþʹÓøÃÎó²îÖ´ÐÐí§ÒâµÄPHP´úÂë¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_OpenMRS_´úÂëÖ´ÐÐ[CVE-2018-19276][CNNVD-201902-602]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OpenMRSÊÇÃÀ¹úOpenMRS¹«Ë¾µÄÒ»Ì׿ªÔ´µÄµç×Ó²¡Àúϵͳ¡£OpenMRSPlatform2.24.0֮ǰ°æ±¾Öб£´æÇå¾²Îó²î¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Billion_5200W-T_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-18372][CNNVD-201905-077]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Billion5200W-T·ÓÉÆ÷ÔÚʱ¼äÉèÖù¦Ð§Öб£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¸ÃÎó²îλÓÚtools_time.aspÒ³Ã棬Զ³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

UDP_DD-WRT_»º³åÇøÒç³öÎó²î[CVE-2021-27137]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

DD-WRTÊÇÒ»¸ö»ùÓÚLinuxµÄÎÞÏß·ÓÉÈí¼þ¡£¸ÃÎó²î£¬Í¨¹ý»º³åÇøÒç³ö¿ÉÖ´ÐÐí§ÒâÏÂÁµ¼ÖÂÖ÷»úÓб»½ÓÊܵÄΣº¦¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Billion_5200W-T_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-18369][CNNVD-201905-073]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Billion5200W-T·ÓÉÆ÷ÔÚÔÚadv_remotelog.aspÎļþÖб£´æδ¾­Éí·ÝÑéÖ¤µÄÏÂÁî×¢Èë¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_OTRS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-16921][CNNVD-201711-917]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÔÚOTRS6.0.xÖÁ6.0.1¡¢OTRS5.0.xÖÁ5.0.24ºÍOTRS4.0.xÖÁ4.0.26ÖУ¬ÒÔÊðÀíÉí·ÝµÇ¼OTRSµÄ¹¥»÷Õß¿ÉÒÔʹÓÃ±íµ¥²ÎÊý£¨ÓëPGPÏà¹Ø£©²¢ÔÚOTRS»òWeb·þÎñÆ÷Óû§µÄȨÏÞÏÂÖ´ÐÐí§ÒâshellÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_HPEÖÇÄÜÖÎÀíÖÐÐÄ_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-7184][CNNVD-202010-863]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

HPEIntelligentManagementCenterÊÇÃÀ¹ú»ÝÆÕÆóÒµ¹«Ë¾£¨HewlettPackardEnterprise£¬HPE£©µÄÒ»Ì×ÍøÂçÖÇÄÜÖÎÀíÖÐÐĽâ¾ö¼Æ»®¡£¸Ã½â¾ö¼Æ»®¿ÉÌṩÕû¸öÍøÂç¹æÄ£µÄ¿ÉÊÓÐÔ£¬ÊµÏÖ¶Ô×ÊÔ´¡¢·þÎñºÍÓû§µÄÖÜÈ«ÖÎÀí¡£HPEIntelligentManagementCenter(iMC)7.3֮ǰ°æ±¾±£´æÇå¾²Îó²î£¬¸ÃÎó²îÔ´ÓÚviewbatchtaskresultdetailfact±í´ïʽÓïÑÔ×¢ÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_FreePBXÇå¾²ÈƹýÎó²î[CVE-2019-19006][CNNVD-201911-1264]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃFreePBXÇå¾²ÈƹýÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£FreePBX£¨Ç°³ÆAsteriskManagementPortal£©ÊÇFreePBXÏîÄ¿µÄÒ»Ì×ͨ¹ýGUI£¨»ùÓÚÍøÒ³µÄͼÐλ¯½Ó¿Ú£©ÉèÖÃAsterisk£¨IPµç»°ÏµÍ³£©µÄ¹¤¾ß¡£FreePBX115.0.16.26¼°Ö®Ç°°æ±¾¡¢14.0.13.11¼°Ö®Ç°°æ±¾ºÍ13.0.197.13¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµÄ»á¼û¿ØÖÆ¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÈƹýÃÜÂëÉí·ÝÑéÖ¤²¢»á¼û·þÎñ¹¦Ð§¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-Link_DIR-859Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-17621][CNNVD-201912-1224]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃD-Link_DIR-859Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£D-LinkDIR-859×°±¸LAN²ãÖзºÆðδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÖ´ÐÐÎó²î¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_VMware_NSX_SD-WAN_Edge_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-6961][CNNVD-201805-1140]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃVMware_NSX_SD-WANEdgeµÄÎó²î¾ÙÐй¥»÷£»VMwareSD-WANEdgeÊÇÒ»¿îÁã½Ó´¥Ê½ÆóÒµ¼¶×°±¸,Äܹ»ÒÔ¾­ÓÉÓÅ»¯µÄ·½·¨Îª×¨ÓС¢¹«¹²»ò»ìÏýÓ¦ÓÃ,ÒÔ¼°ÅÌËãºÍÐéÄ⻯·þÎñÌṩÇå¾²ÅþÁ¬¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ZyXEL-CloudCNM-SecuManager_´úÂë×¢Èë[CVE-2020-15348][CNNVD-202006-1754]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZyxelCNMSecuManager3.1.0ºÍ3.1.1°æ±£´æÓ²±àÂëÉñÃØ¡¢Éí·ÝÑé֤ɥʧ¡¢ºóÃźÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£Í¨¹ýdelete_cpes_by_ids¾ÙÐдúÂë×¢Èë¿ÉÖ´ÐÐí§Òâ´úÂ룬Σº¦Ö÷»úÇå¾²¡£

¸üÐÂʱ¼ä£º

20211026

 

ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_FCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃFCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£FCKeditorÊÇ¿ªÔ´µÄÍøÒ³±à¼­Æ÷£¬±»ÖÚ¶à´øÓб༭¹¦Ð§µÄÍøÕ¾»òÕßCMSʹÓá£FCKeditor±£´æFCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î£¬¹¥»÷ÕßʹÓôËÎó²îÉÏ´«í§ÒâÀàÐÍÎļþ£¬»ñÈ¡Ä¿µÄÍøÕ¾µÄwebshell£¬½øÒ»²½»ñÈ¡ÍøÕ¾¿ØÖÆȨ¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20211026


 

ÊÂÎñÃû³Æ£º

HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£FastJsonÊÇ°¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌص㣬ӦÓùæÄ£ºÜ¹ã¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211026


ɾ³ýÊÂÎñ


1¡¢HTTP_ͨÓÃ_unicodeÈƹý

2¡¢SMB_¾Ü¾ø·þÎñ_Winnuke_¹¥»÷[CVE-1999-0153]