ÿÖÜÉý¼¶Í¨¸æ-2021-12-07

Ðû²¼Ê±¼ä 2021-12-10

ÐÂÔöÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Apache_ShenYu_Admin_δÊÚȨµÇ¼Îó²î_¹¥»÷ʵÑé[CVE-2021-37580][CNNVD-202111-1500]

Çå¾²ÀàÐÍ£º

·ÇÊÚȨ»á¼û/ȨÏÞÈƹý

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃApache_ShenYu_AdminµÄδÊÚȨµÇ¼Îó²î£¬ÈƹýJSONWebToken(JWT)Çå¾²ÈÏÖ¤£¬Ö±½Ó½øÈëϵͳºǫ́

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Dubbo_Hessian2ЭÒé·´ÐòÁл¯Îó²î[CVE-2021-25641]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚͨ¹ý½á¹¹serializationidÀ´¾ÙÐÐδÊÚȨ´úÂëÖ´ÐУ¬Í¨¹ýKryo¡¢FST»òÕßnative-javaµÈÇå¾²ÐԽϲîµÄÐòÁл¯·½·¨¾ÙÐз´ÐòÁл¯´úÂëÖ´ÐУ»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³Ì·þÎñŲÓüƻ®£¬ÒÔ¼°SOA·þÎñÖÎÀí¼Æ»®¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇó¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Dubbo_Nashorn¾ç±¾Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-30181]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÔÚ¿ÉÄÜÒѾ­¿ØÖÆÈçZooKeeperÉèÖÃÖÐÐĺó£¬Í¨¹ýÉèÖÃÖÐÐÄÀ´½á¹¹¶ñÒâÇëÇó¶ÔDubbo×¢ÈëNashorn¾ç±¾£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³Ì·þÎñŲÓüƻ®£¬ÒÔ¼°SOA·þÎñÖÎÀí¼Æ»®¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇó¡£

¸üÐÂʱ¼ä£º

20211207

 


ÊÂÎñÃû³Æ£º

 HTTP_Netgear-ProSAFE-Plus_JGS516PE_δÑéÖ¤Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-26919][CNNVD-202010-350]

Çå¾²ÀàÐÍ£º

·ÇÊÚȨ»á¼û/ȨÏÞÈƹý

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCVE-2020-26919Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£NetgearProSAFEPlusJGS516PE/GS116Ev2ÊÇÃÀ¹úÍø¼þ(Netgear)¹«Ë¾µÄÒ»¿î½»Á÷»ú¡£NetgearJGS516PEdevices2.6.0.43֮ǰ°æ±¾±£´æÇå¾²Îó²î£¬¸ÃÎó²îÔ´ÓÚ×°±¸ÔÚ¹¦Ð§¼¶±ðÉÏÊܵ½È±ÉÙ»á¼û¿ØÖÆ¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_WordPress_XSS¾ç±¾×¢ÈëÎó²î[CVE-2019-16219][CNNVD-201909-549]

Çå¾²ÀàÐÍ£º

XSS¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃNetgea·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£ÔÚNETGEARR7000Éϱ£´æÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Çå¾²Îó²î¡£Îó²îʹÓÃÀֳɺ󣬿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_thinkcmf_ºǫ́´úÂëÖ´ÐÐÎó²î[CVE-2019-7580][CNNVD-201902-163]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃthinkcmfµÄºǫ́´úÂëÖ´ÐÐÎó²î£¬ÔÚ·ÖÀàÖÎÀíÒ³Ã潨Éè·ÖÖÖÓÖÃûʱ£¬Ð´Èë¶ñÒâ´úÂë¡£ThinkCMFÊÇÒ»¿îÖ§³ÖSwooleµÄ¿ªÔ´ÄÚÈÝÖÎÀí¿ò¼Ü(CMF),»ùÓÚThinkPHP¿ª·¢¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Downloader_APT-C-23_ÅþÁ¬_±äÖÖ

Çå¾²ÀàÐÍ£º

ÏÂÔØÕßľÂí

ÊÂÎñÐÎò£º

¼ì²âµ½APT-C-23ÏÂÔØÆ÷ľÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAPT-C-23ÏÂÔØÆ÷ľÂí¡£APT-C-23ÏÂÔØÆ÷ľÂíÊÇÒ»¸ö¹¦Ð§ºÜÊÇÇ¿Ê¢µÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_sys_verifies.php_´úÂë×¢ÈëÎó²î[CVE-2018-9174][CNNVD-201804-087]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DeDeCMS5.7°æ±¾ÔÚ±£´æsys_verifies.php´úÂë×¢ÈëÎó²î£¬¸ÃÎó²îÔ´ÓÚ¶Ô´«Èë²ÎÊýrefiles¹ýÂ˲»ÑϽ÷£¬µ¼Ö¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211207


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Phpcms_insdex.php_ǰ̨Getshell

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚʹÓÃPhpcmsǰ̨ע²áÓû§µÄ½çÃ棬¾ÙÐÐgetshell²Ù×÷£¬µ«ÏÖÔÚ¹æÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñgetshell£»£»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¸ÃÈí¼þ½ÓÄÉÄ£¿é»¯¿ª·¢£¬Ö§³Ö¶àÖÖ·ÖÀà·½·¨£¬Ê¹ÓÃËü¿ÉÀû±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Phpcms_insdex.php_ºǫ́Getshell

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚʹÓÃPhpcmsºǫ́ҳÃ棬¾ÙÐÐgetshell²Ù×÷£¨ÏÖÔڸùæÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñÒѾ­getshell£©£»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¸ÃÈí¼þ½ÓÄÉÄ£¿é»¯¿ª·¢£¬Ö§³Ö¶àÖÖ·ÖÀà·½·¨£¬Ê¹ÓÃËü¿ÉÀû±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_stepselect_main.php_´úÂë×¢ÈëÎó²î[CVE-2018-9175][CNNVD-201804-086]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DeDeCMS5.7°æ±¾ÔÚ±£´æstepselect_main.php´úÂë×¢ÈëÎó²î£¬¸ÃÎó²îÔ´ÓÚ¶Ô´«Èë²ÎÊýegroup¹ýÂ˲»ÑϽ÷£¬µ¼Ö¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211207

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î[CVE-2018-7700][CNNVD-201803-954]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú׿׿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼­¡¢ÖÎÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£DesdevDedeCMS5.7°æ±¾Öб£´æí§Òâ´úÂëÖ´ÐÐÎó²î¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòtag_test_action.phpÎļþ·¢ËÍ¡®partcode¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_VMware_Spring_Cloud_Netflix_´úÂëÖ´ÐÐÎó²î[CVE-2021-22053][CNNVD-202111-1645]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

SpringCloudNetflixÊÇÒ»Ì×ÂþÑÜʽ·þÎñ¿ò¼ÜµÄ·â×°£¬°üÀ¨·þÎñµÄ·¢Ã÷ºÍ×¢²á£¬¸ºÔØƽºâ¡¢¶Ï·Æ÷¡¢REST¿Í»§¶Ë¡¢ÇëÇó·ÓɵÈ¡£¸ÃÎó²îÊÇÓÉÓÚVMwareSpringCloudÔÚͬʱʹÓÃspring-cloud-netflix-hystrix-dashboardºÍspring-boot-starter-thymeleafµÄÓ¦ÓóÌÐòʱ£¬¹ûÕæÁËÔÚÆÊÎöÊÓͼģ°åʱ´úÖ´ÐÐÇëÇóURI·¾¶ÖÐÌá½»½ÓÂëµÄÒªÁì¡£µ±ÔÚ¡®/hystrix/monitor;[user-provideddata]`ÉÏ·¢³öÇëÇóʱ£¬`hystrix/monitor`ºóÃæµÄ·¾¶ÔªËؽ«±»Ê¶±ðΪSpringEL±í´ïʽ£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20211207


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú׿׿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼­¡¢ÖÎÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£DedecmsV5.7SP2°æ±¾ÖеÄtpl.phpÖб£´æ´úÂëÖ´ÐÐÎó²î£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÔÚÔöÌíбêÇ©ÖÐÉÏ´«Ä¾Âí£¬»ñÈ¡webshell¡£¸ÃÎó²îʹÓÃÐèÒªµÇ¼ºǫ́£¬²¢ÇÒºǫ́µÄÕË»§È¨ÏÞÊÇÖÎÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

÷ÈħӰϷ³ÌÐò(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉƵÄÇ¿Ê¢ÊÓƵӰϷϵͳ¡£ÍêÉÆÖ§³ÖÖÚ¶àÊÓƵÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¸ÃÎó²î±¬·¢Ô­ÓÉÓÚ¹ýÂ˲»ÑϽ÷µ¼Ö¹¥»÷Õß¿ÉÒÔÖ±½ÓÔÚÄÚÖÃÄ£°åÖÐ×¢Èë¶ñÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211207


 

ÊÂÎñÃû³Æ£º

HTTP_ÅÀ³æBot»á¼û

Çå¾²ÀàÐÍ£º

ÍøÒ³ÅÀ³æ

ÊÂÎñÐÎò£º

¼ì²âµ½ÅÀ³æBot¶ÔÄ¿µÄIPÖ÷»úµÄweb»á¼û,¿ÉÄÜÔÚ¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐÒ³ÃæÅÀÈ¡¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_TP-LINK_TL-WR840N_EU(V5)_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2021-41653][CNNVD-202111-1211]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

TP-LINKTL-WR840NÊÇÒ»¿îÎÞÏß·ÓÉÆ÷£¬ÐŵÀÊýΪ13£¬Ö§³ÖVPN¹¦Ð§¡£TP-LINKTL-WR840NEU(V5)RouterµÄPING¹¦Ð§±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýIPµØµãÖÐÌØÖƵÄÓÐÓÃÔغÉÖ´ÐÐÔ¶³ÌÏÂÁî¡£

¸üÐÂʱ¼ä£º

20211207

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_º£¿µÍþÊÓIPÉãÏñ»ú/NVR_ÏÂÁî×¢ÈëÎó²î[CVE-2021-36260][CNNVD-202109-1602]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

º£¿µÍþÊÓIPÉãÏñ»ú/NVR×°±¸¹Ì¼þÖб£´æÒ»¸öδÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¬ÓÉÓÚ¶ÔÊäÈë²ÎÊýУÑé²»³ä·Ö£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍ´øÓжñÒâÏÂÁîµÄ±¨Îĵ½ÊÜÓ°Ïì×°±¸£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔµ¼ÖÂÏÂÁîÖ´ÐС£º£¿µÍþÊÓÒÑÐû²¼°æ±¾ÐÞ¸´¸ÃÎó²î£¬¸ÃÎó²î»áÓ°ÏìIPÉãÏñÍ·ºÍNVR×°±¸¹Ì¼þ£¬ÆäÖаüÀ¨2021Äê6ÔµÄ×îй̼þÒÔ¼°2006ÄêÐû²¼µÄ¹Ì¼þ¡£

¸üÐÂʱ¼ä£º

20211207

 

ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

HTTP_Ç徲ɨÃè_WEBɨÃèÆ÷ÐÐΪ

Çå¾²ÀàÐÍ£º

ÍøÂçɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãµÄÖ÷»úÕýÔÚʹÓÃWEBɨÃ蹤¾ß(È磺sqlmap¡¢nessusµÈ)¶ÔÄ¿µÄIPµØµã¾ÙÐÐÎó²îɨÃè¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×ö·þÎñɨÃè¡¢Îó²î²âÊԵȡ£Í¨¹ýÎó²îɨÃ裬¿ÉÒÔ×Ô¶¯¿ìËÙ̽²âһЩ³£¼ûÎó²îÇéÐΣ¬µ±±£´æÎó²îʱ±ãÓÚºóÐø¾ÙÐÐʹÓù¥»÷¡£

¸üÐÂʱ¼ä£º

20211207