ÿÖÜÉý¼¶Í¨¸æ-2022-07-28
Ðû²¼Ê±¼ä 2022-07-28
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_docker_Ô¶³Ì·ÇÊÚȨ»á¼û |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | dockerswarmÊÇdockerϵÄÂþÑÜ»¯Ó¦ÓõÄÍâµØ¼¯Èº£¬ÔÚ¿ª·Å2375¼àÌý¼¯ÈºÈÝÆ÷ʱ£¬Èô½«¸Ã¶Ë¿Ú̻¶ÔÚ¹«ÍøÉÏÔò»áµ¼ÖÂδÊÚȨ»á¼û£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¹¥»÷·þÎñÆ÷ÒÔ»ñȡȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_×¢Èë¹¥»÷_ìøµÀv16.5_sql×¢Èë[CNVD-2022-42853] |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ìøµÀPMS£¨ZenTaoProjectManagementSystem£©ÊÇÒ»¿îÖÐСÐÍÆóÒµÏîÄ¿ÖÎÀí¹¤¾ß£¬¼¯²úÆ·ÖÎÀí¡¢ÏîÄ¿ÖÎÀí¡¢²âÊÔÖÎÀíÓÚÒ»Éí£¬Í¬Ê±°üÀ¨ÊÂÎñÖÎÀí¡¢×éÖ¯ÖÎÀíµÈÖî¶à¹¦Ð§¡£ÔÚìøµÀ16.5µÄ°æ±¾Öб£´æsql×¢ÈëÎó²î£¬¸ÃÎó²î±¬·¢Ôµ¹ÊÔÓÉÊÇδ¶ÔÊäÈëµÄaccount²ÎÊýÄÚÈÝ×÷¹ýÂËУÑ飬µ¼Ö¹¥»÷ÕßÆ´½Ó¶ñÒâSQLÓï¾ä£¬Í¨¹ýSQLÓï¾ä£¬ÊµÏÖÎÞÕ˺ŵǼ£¬ÉõÖÁ¸Ä¶¯Êý¾Ý¿â¡¢Äõ½Ä¿µÄ×°±¸È¨ÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢V9_uploaderOperate."font-size:13px;font-family:'Arial','sans-serif'">ÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓ÷ºÎ¢V9µÄuploaderOperate."font-size:13px;font-family:'Arial','sans-serif'">·¾¶µÄÎļþÉÏ´«Îó²îÉÏ´«¿ÉÒÉÎļþ¡£·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒƶ¯°ì¹«Õý̨¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA-V9-UploadFile."font-size:13px;font-family:'Arial','sans-serif'">ÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐUploadFile."font-size:13px;font-family:'Arial','sans-serif'">±£´æÎó²î£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«webshell£¬»ñÈ¡Ä¿µÄϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | DNS_ľÂíºóÃÅ_BlueDwarf_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅBlueDwarf¡£BlueDwarfÊÇÒ»¸ö¹¦Ð§ºÜÊÇÇ¿Ê¢µÄºóÃÅ£¬Ê¹ÓÃDNSÐÒéÓëC&C·þÎñÆ÷ͨѶ¡£ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA-V9-eimupload."font-size:13px;font-family:'Arial','sans-serif'">ÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐeimupload."font-size:13px;font-family:'Arial','sans-serif'">±£´æÎó²î£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«webshell£¬»ñÈ¡Ä¿µÄϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA-V9-eimdocupload."font-size:13px;font-family:'Arial','sans-serif'">ÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐeimdocupload."font-size:13px;font-family:'Arial','sans-serif'">±£´æÎó²î£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«webshell£¬»ñÈ¡Ä¿µÄϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA-V9-eimuploadformobile."font-size:13px;font-family:'Arial','sans-serif'">ÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐeimuploadformobile."font-size:13px;font-family:'Arial','sans-serif'">±£´æÎó²î£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«webshell£¬»ñÈ¡Ä¿µÄϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Linux¿ÉÒÉÏÂÁîÖ´Ðй¥»÷ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ÏÂÁî×¢Èë¹¥»÷£¬ÊÇÖ¸ÕâÑùÒ»ÖÖ¹¥»÷ÊֶΣ¬ºÚ¿Íͨ¹ý°ÑϵͳÏÂÁî¼ÓÈëµ½webÇëÇóÒ³ÃæÍ·²¿ÐÅÏ¢ÖУ¬Ò»¸ö¶ñÒâºÚ¿ÍÒÔʹÓÃÕâÖÖ¹¥»÷ÒªÁìÀ´²»·¨»ñÈ¡Êý¾Ý»òÕßÍøÂ硢ϵͳ×ÊÔ´¡£null |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉ¿ÉÖ´ÐÐÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÖ÷»ú±£´æÉÏ´«¿ÉÒÉwebshellµ½Ä¿µÄipÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_Java_ShellcodeÍâµØÀú³Ì×¢Èë |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWindowsVirtualMachineÀàÖеÄenqueueÒªÁì¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐJavaÍâµØÀú³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄpayload£¬Ê¹ÓöñÒâÀà¾ÙÐÐÀú³Ì×¢ÈëÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬»ñȡϵͳ¿ØÖÆȨ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ÓÃÓÑNC_ServiceDispatcherServlet_·´ÐòÁл¯Ê¹Óà |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNCµÄaccept."font-size:13px;font-family:'Arial','sans-serif'">·¾¶µÄÎļþÉÏ´«Îó²îÉÏ´«¿ÉÒÉÎļþ¡£ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳ¡£ |
¸üÐÂʱ¼ä£º | 20220728 |
ÊÂÎñÃû³Æ£º | HTTP_Acunetix11_AWVS11_Content_WebÎó²îɨÃè2 |
Çå¾²ÀàÐÍ£º | Ç徲ɨÃè |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃAcunetix11(AWVS11)Îó²îɨÃ蹤¾ß¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐWebÓ¦ÓÃÎó²îɨÃèµÄÐÐΪ£¬ÊµÑéɨÃè·¢Ã÷WebÓ¦ÓÃϵͳÎó²î£¬Îª½øÒ»²½ÈëÇÖÄ¿µÄIPÖ÷»ú×ö×¼±¸¡£Acunetix11(AWVS11)ÊÇÒ»¿îÉÌÓõÄÕë¶ÔWebÓ¦ÓõÄÇå¾²Îó²îɨÃèÈí¼þ¡£ÊµÑéͨ¹ýWebÎó²îɨÃ裬·¢Ã÷WebÓ¦ÓÃϵͳÎó²î¡£ |
¸üÐÂʱ¼ä£º | 20220728 |