ÿÖÜÉý¼¶Í¨¸æ-2021-11-30

Ðû²¼Ê±¼ä 2021-12-10

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_´úÂëÖ´ÐÐ[CVE-2017-6361][CNNVD-201702-940]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý £¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁîÖ´ÐÐ[CVE-2017-6360][CNNVD-201702-941]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý £¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî £¬»ñÈ¡ÖÎÀíԱȨÏÞºÍÃô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁîÖ´ÐÐ[CVE-2017-6359][CNNVD-201702-942]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý £¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡ÖÎÀíԱȨÏÞ £¬Ö´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

 TCP_Çå¾²Îó²î_Hadoop_Yarn_RPCδÊÚȨ»á¼ûÎó²î

Çå¾²ÀàÐÍ£º

·ÇÊÚȨ»á¼û/ȨÏÞÈƹý

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃHadoopYarnµÄÎó²î¾ÙÐÐδÊÚȨ»á¼û£»¹ØÓÚ8032̻¶ÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager £¬±àдӦÓóÌÐòŲÓÃyarnClient.getApplications()¼´¿ÉÉó²éËùÓÐÓ¦ÓÃÐÅÏ¢£»Hadoop×÷Ϊһ¸öÂþÑÜʽÅÌËãÓ¦Óÿò¼Ü £¬ÖÖÀ๦Ч·±¶à £¬¶øHadoopYarn×÷ΪÆä½¹µã×é¼þÖ®Ò»¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_CouchDB_JSON_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-12636][CNNVD-201711-486]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃApacheCouchDBJSONÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â £¬×¨×¢ÓÚÒ×ÓÃÐԺͳÉΪ"ÍêÈ«Óµ±§webµÄÊý¾Ý¿â"¡£CouchDB»áĬÈÏ»áÔÚ5984¶Ë¿Ú¿ª·ÅRestfulµÄAPI½Ó¿Ú £¬ÓÃÓÚÊý¾Ý¿âµÄÖÎÀí¹¦Ð§¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌà £¬JavaScript×÷ΪÅÌÎÊÓïÑÔ £¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£CouchDB½ÓÄÉ»ùÓÚErlangµÄJSONÆÊÎöÆ÷ £¬Óë»ùÓÚJavaScriptµÄJSONÆÊÎöÆ÷²î±ð £¬CouchDB¿ÉÒÔÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇÉ«Öظ´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ»á¼û¿ØÖÆ £¬ÉõÖÁ°üÀ¨ÌåÏÖÖÎÀíÓû§µÄ_admin½ÇÉ«¡£¶ñÒâ¹¥»÷ÕßʹÓÃÕâÒ»¹¦Ð§²¢ÍŽáCVE-2017-12636Îó²î £¬¿ÉÒÔʹ·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý»á¼û·þÎñÆ÷ÉϵÄí§ÒâshellÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear_Nighthawk_R7000δÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-31802]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃNetgea·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£ÔÚNETGEARR7000Éϱ£´æÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Çå¾²Îó²î¡£Îó²îʹÓÃÀֳɺó £¬¿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

 HTTP_Çå¾²Îó²î_Primefaces_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-1000486][CNNVD-201801-112]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

PrimeFacesÊÇÒ»¸ö¿ªÔ´Óû§½çÃæ(UI)×é¼þ¿â £¬ÓÃÓÚ»ùÓÚJavaServerFacesµÄÓ¦ÓóÌÐò £¬ÓÉÍÁ¶úÆ乫˾PrimeTekInformatics½¨Éè¡£Primefaces5.x±£´æÈõ¼ÓÃÜÎó²î £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-Link_DWL-2600AP_²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î[CVE-2019-20499/CVE-2019-20500/CVE-2019-20501][CNNVD-202003-201/CNNVD-202003-205/CNNVD-202003-204]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

D-LinkDWL-2600APÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß½ÓÈëµã×°±¸¡£D-LinkDWL-2600AP4.2.0.15RevA°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¹¥»÷Õ߿ɽèÖúÉúÑÄÉèÖù¦Ð§Ê¹ÓøÃÎó²îÖ´ÐÐí§ÒâµÄ²Ù×÷ϵͳÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Terramaster_TOS_ÏÂÁî×¢ÈëÎó²î[CVE-2020-35665]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×ÓÊÖÒÕ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ £¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýÔÚÊÂÎñ²ÎÊýÖаüÀ¨makecvs.php×¢Èë²Ù×÷ϵͳÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_SQL_Server_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0618][CNNVD-202002-496]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØϵÊý¾Ý¿âÖÎÀíϵͳ(RDBMS) £¬ÊÇÏÖÔÚÌìÏÂÉÏÆÕ±éʹÓõÄÊý¾Ý¿âÖ®Ò»¡£¸ÃÎó²îÔ´ÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢ËÍÈ«ÐĽṹµÄÇëÇó £¬¿ÉʹÓôËÎó²îÔÚ±¨±í·þÎñÆ÷·þÎñÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_ÆïÊ¿CMSÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-35339][CNNVD-202102-1295]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÆïÊ¿CMSµÄ¡°ÍøÕ¾ÓòÃû¡±¶ÔÓ¦²ÎÊý¾ÙÐдúÂëÖ´ÐвÙ×÷£»ÆïÊ¿È˲ÅϵͳÊÇÒ»Ïî»ùÓÚPHPMYSQLΪ½¹µã¿ª·¢µÄÒ»Ì×Ãâ·Ñ¿ªÔ´×¨ÒµÈ˲ÅÕÐƸϵͳ¡£ÎªÐ¡ÎÒ˽¼ÒÇóÖ°ºÍÆóÒµÕÐƸÌṩÐÅÏ¢»¯½â¾ö¼Æ»®,ÆïÊ¿È˲Åϵͳ¾ß±¸Ö´ÐÐЧÂʸߡ¢Ä£°åÇл»×ÔÓÉ¡¢ºǫ́ÖÎÀí¹¦Ð§ÎÞа¡¢Ä£¿é¹¦Ð§Ç¿Ê¢µÈÌصã¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_XStream_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-26217][CNNVD-202011-1441]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

Xstream½â×éʱ´¦Öóͷ£µÄÁ÷°üÀ¨ÀàÐÍÐÅÏ¢ÒÔÖØн¨ÉèÒÔÇ°±àдµÄ¹¤¾ß¡£XStreamÒò´Ë»ùÓÚÕâЩÀàÐÍÐÅÏ¢½¨ÉèÐÂʵÀý¡£¹¥»÷Õß¿ÉÒÔʹÓô¦Öóͷ£¹ýµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢Èë¿ÉÒÔÖ´ÐÐí§ÒâshellÏÂÁîµÄ¹¤¾ß¡£

¸üÐÂʱ¼ä£º

20211130


ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÏÂÁîÎó²î

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

÷ÈħӰϷ³ÌÐò(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉƵÄÇ¿Ê¢ÊÓƵӰϷϵͳ¡£ÍêÉÆÖ§³ÖÖÚ¶àÊÓƵÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ) £¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¸ÃÎó²îÖ÷ÒªµÄ±¬·¢Ôµ¹ÊÔ­ÓÉÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£

¸üÐÂʱ¼ä£º

20211130