ÿÖÜÉý¼¶Í¨¸æ-2022-05-03

Ðû²¼Ê±¼ä 2022-05-03

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_VMware-Workspace-ONE-Access_Ä£°å×¢Èë_ÏÂÁîÖ´ÐÐ[CVE-2022-22954][CNNVD-202204-2551]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

VMwareWorkspaceONEAccess£¨ÒÔÇ°³ÆΪVMwareIdentityManager£©Ö¼ÔÚͨ¹ý¶àÒòËØÉí·ÝÑéÖ¤¡¢Ìõ¼þ»á¼ûºÍµ¥µãµÇ¼ £¬ÈÃÄúµÄÔ±¹¤¸ü¿ìµØ»á¼ûSaaS¡¢WebºÍ±¾»úÒƶ¯Ó¦ÓóÌÐò¡£CVE-2022-22954ÊÇÒ»¸öÄäÃû·þÎñÆ÷Ä£°å×¢ÈëÎó²î £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î¾ÙÐÐÔ¶³Ìí§Òâ´úÂëÖ´ÐС£ÊÜÓ°Ïì°æ±¾ÈçÏ£ºVMwareWorkspaceONEAccessAppliance£¨°æ±¾ºÅ£º20.10.0.0 £¬20.10.0.1 £¬21.08.0.0 £¬21.08.0.1£©VMwareIdentityManagerAppliance£¨°æ±¾ºÅ£º3.3.3 £¬3.3.4 £¬3.3.5 £¬3.3.6£©VMwareRealizeAutomation£¨°æ±¾ºÅ£º7.6£©

¸üÐÂʱ¼ä£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_WSO2-fileupload_í§ÒâÎļþÉÏ´«[CVE-2022-29464][CNNVD-202204-3737]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

WSO2-APIManagerÊÇÃÀ¹úWSO2¹«Ë¾µÄÒ»Ì×APIÉúÃüÖÜÆÚÖÎÃ÷È·¾ö¼Æ»®¡£WSO2-APIManager±£´æÇå¾²Îó²î £¬¸ÃÎó²îÔÊÐíÎÞÏÞÖƵÄÎļþÉÏ´«´Ó¶øÔ¶³Ì´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20220503


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Webshell_AntswordľÂí_

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Á÷Á¿Öмì²âµ½AntswordµÄ¿ØÖÆÏÂÁî £¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ¾ÙÐÐÅþÁ¬ÐÐΪ¡£¸ÃWebshellÖ÷Ҫͨ¹ýJavaÖÐJSÒýÇæʵÏÖµÄÒ»¾ä»°Ä¾Âí £¬¸ÄÉÆÁ˹Űå½á¹¹×Ö½ÚÂë·½·¨ÌØÕ÷ÏÔ×Å £¬payloadÈÝÁ¿´óµÈÈõµã¡£

¸üÐÂʱ¼ä£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÒÚÓʵç×ÓÓʼþϵͳ_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÒÚÓʵç×ÓÓʼþϵͳͨ¹ýÐÞ¸ÄcookieÔÚÄ¿µÄipÖ÷»úÖ´ÐÐÔ¶³Ì´úÂëÖ´ÐвÙ×÷ £¬ÒÚÓʵç×ÓÓʼþϵͳÊÇÓɱ±¾©ÒÚÖÐÓÊÐÅÏ¢ÊÖÒÕÓÐÏÞ¹«Ë¾£¨ÒÔϼò³ÆÒÚÓʹ«Ë¾£©¿ª·¢µÄÒ»¿îÃæÏòÖдóÐͼ¯ÍÅÆóÒµ¡¢Õþ¸®¡¢¸ßУÓû§µÄ¹ú²úÓʼþϵͳ¡£ÒÚÓʵç×ÓÓʼþϵͳ½ÓÄÉÁË×ÔÖ÷Ñз¢MTAÒýÇæ¡¢ÂþÑÜʽÎļþϵͳ´æ´¢·½·¨¡¢¶à¶ÔÁлúÖÆ¡¢ECS´æ´¢×Óϵͳ¡¢CacheϵͳµÈ¶àÏî½¹µãÊÖÒÕ £¬ÌṩÁ˸»ºñµÄÓʼþ¹¦Ð§¡£

¸üÐÂʱ¼ä£º

20220503


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_TamronOS-IPTVϵͳ_í§ÒâÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TamronOSIPTV/VODϵͳÊÇÒ»Ì×»ùÓÚLinuxÄں˿ª·¢µÄ¿í´øÔËÓªÉÌ¡¢Âùݡ¢Ñ§Ð£Ö±²¥µã²¥Ò»Ìå½â¾ö¼Æ»®¡£TamronOSIPTVϵͳapi/ping±£´æí§ÒâÏÂÁîÖ´ÐÐÎó²î £¬¹¥»÷Õßͨ¹ýÎó²î¿ÉÒÔÖ´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220503


ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_BillGates_¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½BillGatesµÄC&C·þÎñÆ÷ÊÔͼ·¢ËÍ¿ØÖÆÏÂÁî¸øBillGates £¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçBillGates¡£BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂç £¬Ö÷Òª¹¦Ð§ÊÇÕë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐDDoS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_PhpTax_pfilez²ÎÊý_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PhpTax0.8°æ±¾Öб£´æÒ»¸öÔ¶³Ì´úÂë×¢ÈëÎó²î £¬¸ÃÎó²îÔ´ÓÚÔÚÌìÉúPDFʱ £¬drawimage.phpÖеÄicondrawpng()º¯ÊýÎÞ·¨×¼È·´¦Öóͷ£pfilez²ÎÊý £¬¸Ã²ÎÊý½«ÔÚexec()Óï¾äÖÐʹÓ᣹¥»÷Õß¿ÉÒÔͨ¹ýÔÚpfilez²ÎÊý×¢Èë¶ñÒâÄÚÈÝʵÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20220503


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_MobileIron_MDM_·´ÐòÁл¯Îó²î[CVE-2020-15505][CNNVD-202007-291]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃMobileIron_MDMµÄ·´ÐòÁл¯Îó²î £¬¸ÃÎó²îµÄ³ÉÒòÊÇMobileIron_MDMʹÓÃÁËHessianЭÒéµÄJavaÖеÄí§Òâ·´ÐòÁл¯¡£MobileIronÊÇÈ«ÇòÁìÏÈÇÒÉú³¤×îѸËÙµÄÒƶ¯IT½â¾ö¼Æ»®³§ÉÌÖ®Ò» £¬ÔÚÈ«ÇòÓнü20000¼Ò¹«Ë¾Ê¹ÓÃMobileIronµÄÒƶ¯×°±¸ÖÎÃ÷È·¾ö¼Æ»®£¨MDM£©¡£

¸üÐÂʱ¼ä£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_PHPCMS_v2008_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-19127][CNNVD-201811-248]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃPHPCMS_v2008í§Òâ´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ £¬¸ÃÎó²îʹÓÃtype.phpÎļþ½á¹¹¶ñÒ⻺´æÎļþ £¬»á¼û¸Ã»º´æÎļþ¿ÉÒÔ»ñÈ¡Óû§È¨ÏÞ¡£PHPCMSÊÇ¿ªÔ´µÄÕûվϵͳ¡£PHPCMS±£´æPHPCMS_v2008í§Òâ´úÂëÖ´ÐÐÎó²î £¬¹¥»÷ÕßʹÓôËÎó²îÇÔÈ¡Ãô¸ÐÐÅÏ¢ £¬»ñÈ¡Êý¾Ý¿âºÍÖÎÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220503

 

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netlink_GPON·ÓÉÆ÷ÏÂÁî×¢ÈëÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Netlink-GPON·ÓÉÆ÷µÄWeb·þÎñ±£´æÏÂÁî×¢ÈëÎó²î £¬¹¥»÷Õß¿Éͨ¹ýÏòÇëÇóÌåÖеÄÌض¨Î»ÖòåÈë¶ñÒâÔغÉ £¬Ö´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_ͨ´ïOA_í§ÒâÎļþÉÏ´«/Îļþ°üÀ¨Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ͨ´ïOAÊÇÒ»Ìװ칫ϵͳ¡£ÓÉÓÚͨ´ïOAÖб£´æµÄÁ½Ã¶Îó²î(ÎļþÉÏ´«Îó²î £¬Îļþ°üÀ¨Îó²î) £¬¹¥»÷Õß¿Éͨ¹ýÕâÁ½Ã¶Îó²îʵÏÖÔ¶³ÌÏÂÁîÖ´ÐС£/ispirit/im/upload.php±£´æÈƹýµÇ¼(í§ÒâÎļþÉÏ´«Îó²î) £¬ÍŽágateway.php´¦±£´æµÄÎļþ°üÀ¨Îó²î £¬×îÖÕµ¼ÖÂgetshell¡£

¸üÐÂʱ¼ä£º

20220503

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ExifTool_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-22204]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ExifToolÊÇÒ»¸ö×ÔÁ¦ÓÚƽ̨µÄPerl¿â £¬Ò²ÓÐÒ»¸öÏÂÁîÐÐÓ¦ÓóÌÐò £¬ÓÃÓÚ¶ÁÈ¡ £¬Ð´ÈëºÍ±à¼­ÖÖÖÖÎļþÖеÄÔªÐÅÏ¢¡£¸ÃÎó²îÊÇÓÉÓÚExifTool°æ±¾7.44°æ±¾Öб£´æ¶ÔDjVuÎļþÃûÌõÄÊý¾Ý´¦Öóͷ£²»µ±¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚº¬ÓÐÎó²î°æ±¾µÄExifTool¿âµÄÓ¦Ó÷þÎñÆ÷»òÕßÓ¦ÓóÌÐòÏ £¬½á¹¹¶ñÒâDjVuÎļþ £¬·þÎñÆ÷»òÕßÓ¦ÓóÌÐòÔ¶³ÌÍâµØÆÊÎö´ËÎļþ £¬µ¼ÖÂí§Òâ´úÂëÖ´ÐÐ £¬×îÖÕ»ñÈ¡·þÎñÆ÷×î¸ßȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220503