ÿÖÜÉý¼¶Í¨¸æ-2022-11-22
Ðû²¼Ê±¼ä 2022-11-22ÊÂÎñÃû³Æ£º TCP_ºóÃÅ_Beacon.Payload_ÅþÁ¬
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½Ä¿µÄIPÖ÷»úÊÔͼÏòÔ´IPÖ÷»ú´«ÊäºóÃÅ¡£³£¼ûµÄBeacon°üÀ¨CobaltStrikeµÄBeacon£¬ÒÔ¼°MetasploitµÄMeterpreterµÈ¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_Apache_Flink_СÓÚ1.11.2_í§ÒâÎļþ¶ÁÈ¡[CVE-2020-17519][CNNVD-202101-271]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ApacheFlink1.11.0,1.11.1,1.11.2°æ±¾ÔÊÐí¹¥»÷Õßͨ¹ýJobManagerÀú³ÌµÄRESTAPI¶ÁÈ¡JobManagerÍâµØÎļþϵͳÉϵÄÈκÎÎļþ£¨JobManagerÀú³ÌÄÜ»á¼ûµ½µÄ£©¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_SQLiteManager_1.2.0_Ŀ¼´©Ô½[CVE-2007-1232]
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSQLiteManagerµÄĿ¼´©Ô½Îó²î»á¼ûÃô¸ÐÎļþ¡£SQLiteManager1.2.0°æ±¾ÖеÄĿ¼±éÀúÎó²îÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýSQLiteManager_currentThemeÖеÄ..¶ÁÈ¡í§ÒâÎļþ¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Apache_CouchDB_JSON_ÏÂÁîÖ´ÐÐ[CVE-2017-12636][CNNVD-201711-486]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉÏApacheCouchDBµÄRestfulµÄAPI½Ó¿Ú±£´æµÄÎó²î£¬½á¹¹¶ñÒâJsonÃûÌõÄÊý¾Ý£¬´Ó¶øʹ·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý»á¼û·þÎñÆ÷ÉϵÄí§ÒâshellÏÂÁî¡£CouchDBÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌã¬JavaScript×÷ΪÅÌÎÊÓïÑÔ£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£CouchDB½ÓÄÉ»ùÓÚErlangµÄJSONÆÊÎöÆ÷£¬Óë»ùÓÚJavaScriptµÄJSONÆÊÎöÆ÷²î±ð£¬CouchDB¿ÉÒÔÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇÉ«Öظ´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ»á¼û¿ØÖÆ£¬ÉõÖÁ°üÀ¨ÌåÏÖÖÎÀíÓû§µÄ_admin½ÇÉ«¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_ÖÂÔ¶OA_ajax.do_δÊÚȨ»á¼û
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÕýÔÚʹÓÃÖÂÔ¶OAV8.0ÒÔÏ°汾µÄδÊÚȨÎó²î»ñȡȨÏÞÀ´¾ÙÐнøÒ»²½ÎļþÉÏ´«µÄ¹¥»÷£»ÖÂÔ¶OA°ì¹«×Ô¶¯»¯Èí¼þ£¬ÓÃÓÚOA°ì¹«×Ô¶¯»¯Èí¼þµÄ¿ª·¢ÏúÊÛ¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_ÈôÒÀCMS_СÓÚ4.5.1_Îļþ¶ÁÈ¡[CNVD-2021-01931]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÈôÒÀCMS<4.5.1°æ±¾ÖеÄí§ÒâÎļþ¶ÁÈ¡Îó²î£¬µÇ¼ºǫ́ºó£¬¿ÉÒÔ¶ÁÈ¡·þÎñÆ÷ÉϵÄí§ÒâÎļþ¡£ÈôÒÀÖÎÀíϵͳÊÇ»ùÓÚSpringBootµÄȨÏÞÖÎÀíϵͳ¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange_Servers_ÏÂÁîÖ´ÐÐ[CVE-2022-40140][CVE-2022-41082]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ExchangeServerÊÇ΢Èí¹«Ë¾µÄÒ»Ì×µç×ÓÓʼþ·þÎñ×é¼þ,ÊǸöÐÂÎÅÓëÐ×÷ϵͳ¡£¸Ãϵͳ±£´æÎó²î£¬¿ÉÔÚ¾ÓÉExchangeServerÉí·ÝÑéÖ¤²¢ÇÒ¾ßÓÐPowerShell²Ù×÷ȨÏÞµÄÇéÐÎÏÂʹÓÃÕâЩÎó²î£¨×éºÏʹÓã©Ô¶³ÌÖ´ÐжñÒâ´úÂ룺CVE-2022-41040£ºMicrosoftExchangeServer·þÎñÆ÷¶ËÇëÇóαÔì(SSRF)Îó²î£¬CVE-2022-41082£ºMicrosoftExchangeServerÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯Èƹý[CVE-2019-2725][CNNVD-201904-1251]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º OracleWebLogicServerÊÇOracleCorporationÄ¿½ñ¿ª·¢µÄJavaEEÓ¦Ó÷þÎñÆ÷¡£OracleWebLogicServer10.3.6.0.0¡¢OracleWebLogicServer12.1.3.0.0°æ±¾±£´æ·´ÐòÁл¯Îó²î£¬¸ÃÎó²îÈƹýCVE-2019-2725²¹¶¡£¬Îó²î±£´æwls-wsatºÍbea_wls9_async_response×é¼þ£¬Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄ¶ñÒâHTTPÇëÇ󣬻ñÈ¡·þÎñÆ÷ȨÏÞ£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º SMTP_ÇÔÃÜľÂí_Snake_Keylogger_ÉÏ´«ÇÔÃÜÐÅÏ¢
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½SnakeKeyloggerÇÔÃÜľÂíÕýÔÚÏòÔ¶³Ì·þÎñÆ÷ÉÏ´«ÇÔÃܵÄÖÖÖÖÐÅÏ¢¡£Snake¶ñÒâÈí¼þÊÇÒ»ÖÖÒÔ.NET±à³ÌÓïÑÔʵÏÖµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£Í¨¹ýÍøÂç´¹ÂÚÓʼþ·Ö·¢¡£SnakeÊÇÒ»ÖÖ¹¦Ð§¸»ºñµÄ¶ñÒâÈí¼þ£¬¶ÔÓû§µÄÒþ˽ºÍÇå¾²×é³ÉÖØ´óÍþв¡£Snake¾ßÓмͼ»÷¼üÒÔ¼°¼ôÌù°åÊý¾Ý¡¢ÆÁÄ»½ØͼºÍƾ֤͵ÇÔ¹¦Ð§¡£Snake¿ÉÒÔ´Ó50¶à¸öÓ¦ÓóÌÐòÖÐÇÔȡƾ֤£¬ÆäÖаüÀ¨FTP¿Í»§¶Ë¡¢Óʼþ¿Í»§¶Ë¡¢Í¨Ñ¶Æ½Ì¨ºÍWebä¯ÀÀÆ÷µÈÓ¦ÓóÌÐò¡£SnakeÖ§³Öͨ¹ý¶àÖÖÐÒé¾ÙÐÐÉÏ´«Êý¾Ý£¬ÀýÈçFTP¡¢SMTPºÍTelegramÈýÖÖ·½·¨ÉÏ´«ÇÔÈ¡µÄÐÅÏ¢¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_fileDownload.jsp_ÎļþÏÂÔØ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉϵķºÎ¢OAfileDownload.jsp±£´æµÄí§ÒâÎļþÏÂÔØÎó²î¡£¹¥»÷Õß¿ÉÒÔͨ¹ý..\/À´Èƹý·ºÎ¢¶Ô../µÄÏÞÖÆ£¬´Ó¶øʵÏÖí§ÒâÎļþÏÂÔØ¡£·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒƶ¯°ì¹«Õý̨¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_Ecology_weaver.eui.EuiServlet_ÎļþÉÏ´«
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉϵķºÎ¢OA_EcologyÉϺǫ́±£´æµÄÎļþÉÏ´«Îó²îÉÏ´«í§ÒâÎļþ£¬´Ó¶ø»ñȡȨÏÞ¡£·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒƶ¯°ì¹«Õý̨¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Apache_Spark_´úÂëÖ´ÐÐ[CVE-2020-9480]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ApacheSparkÊÇÒ»¸ö¿ªÔ´¼¯ÈºÔËËã¿ò¼Ü¡£ÔÚApacheSpark2.4.5ÒÔ¼°¸üÔç°æ±¾ÖÐSparkµÄÈÏÖ¤»úÖƱ£´æȱÏÝ£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¹¥»÷ÕßʹÓøÃÎó²î£¬¿ÉÔÚδÊÚȨµÄÇéÐÎÏ£¬ÔÚÖ÷»úÉÏÖ´ÐÐÏÂÁÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ºóÃÅ_Yakes.qwqÅþÁ¬
Çå¾²ÀàÐÍ£º ÆäËûÊÂÎñ
ÊÂÎñÐÎò£º ¸ÃÊÂÎñÅú×¢£¬Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£¸ÃÊÂÎñÔ´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅYakes.qwq¡£Yakes.qwqÊÇ»ùÓÚIRCÐÒéµÄºóÃÅ£¬ÔËÐк󣬰Ñ×ÔÉí´úÂë²åÈ뵽ϵͳÕý³£Àú³Ì¡£ÅþÁ¬Ô¶³ÌIRCÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷£¬ÎüÊÕÆäÖ¸Á²¢Ö´ÐС£ÈçÏÂÔضñÒâÈí¼þ£¬ÌᳫDDOS¹¥»÷¡£±¾ºóÃÅÔËÐкó£¬Ê×ÏȽ¨Éè¼Ù½ÓÄÉÕ¾Îļþ¼Ð£¬²¢¿½±´×ÔÉíµ½¸ÃÎļþ¼ÐÏ£¬µÖ´ïÒþ²ØµÄÄ¿µÄ¡£ÉèÖÃ×¢²á±í£¬ÊµÏÖ¿ª»úÆô¶¯Òþ²ØÔÚ¼Ù½ÓÄÉÕ¾ÀïµÄºóÃųÌÐò¡£ÎüÊÕ²¢Ö´ÐÐIRC·þÎñÆ÷µÄÖ¸Áî¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ľÂíºóÃÅ_webshell_Altman_PHPÅþÁ¬
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýWebshellÖÎÀí¹¤¾ßAltman»á¼ûÄ¿µÄÖ÷»úÉϵÄÒ»¾ä»°Webshell£¬´Ó¶ø»ñµÃÖ´ÐдúÂë¡¢ÉÏ´«ÏÂÔØÎļþµÈȨÏÞ¡£Altman»ùÓÚ.Net4.0¿ª·¢£¬Õû¸ö³ÌÐò½ÓÄÉmef²å¼þ¼Ü¹¹¡£ÏÖÔÚÍê³ÉµÄ¹¦Ð§ÓУºShellÖÎÀí¡¢ÏÂÁîÖ´ÐС¢ÎļþÖÎÀí¡¢Êý¾Ý¿âÖÎÀí¡¢±àÂëÆ÷µÈ£¬¾ç±¾ÀàÐÍÖ§³Öasp¡¢aspx¡¢php¡¢jsp¡¢python¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_Snews_CMS_ÎļþÉÏ´«¹¥»÷
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSnewsCMSÖеÄÎļþÉÏ´«Îó²î£¬ÉÏ´«¶ñÒâÎļþ£¬´Ó¶ø»ñµÃÄ¿µÄIPÖ÷»úµÄÖ´ÐдúÂë¡¢ÎļþÉÏ´«¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£sNewsÊÇÒ»ÍêÈ«µØ×ÔÓɵġ¢Çкϱê×¼µÄ¡¢Ê¹ÓÃPHPºÍMySQLÇý¶¯µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_PHP_chrº¯Êý_webshellÎļþÉÏ´«
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃchrº¯Êý½á¹¹¶ñÒâÎļþÈƹýÒªº¦´Ê¼ì²â£¬ÉÏ´«PHP¶ñÒâÎļþ£¬´Ó¶ø»ñµÃÄ¿µÄIPÖ÷»úµÄÖ´ÐдúÂë¡¢ÎļþÉÏ´«¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_Zabbix_Server_trapper_ÏÂÁîÖ´ÐÐ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃZabbixµÄÎó²î¾ÙÐжñÒâÏÂÁîÖ´ÐС£ZabbixÊÇÓÉAlexeiVladishev¿ª·¢µÄÒ»ÖÖÍøÂç¼àÊÓ¡¢ÖÎÀíϵͳ£¬»ùÓÚServer-Client¼Ü¹¹¡£ÔÚCVE-2017-2824ÖУ¬ÆäServer¶Ëtrappercommand¹¦Ð§±£´æÒ»´¦´úÂëÖ´ÐÐÎó²î£¬¶øÐÞ¸´²¹¶¡²¢²»ÍêÉÆ£¬µ¼Ö¿ÉÒÔʹÓÃIPv6¾ÙÐÐÈƹý£¬×¢Èëí§ÒâÏÂÁî¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_Alibaba_Canal-config_ÔÆÃÜÔ¿_ÐÅϢй¶
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º canalÊÇ°¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌ⣬¹¥»÷Õß¿Éͨ¹ýÌض¨µÄµØµã»á¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_¿ÉÒÉ·´µ¯shellÏÂÁî×¢Èë_¹¥»÷ʧ°Ü
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐBASH_·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£·´µ¯ÅþÁ¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨·þÎñ¶Ë£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕߵķþÎñ¶Ë³ÌÐò¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£µ±Ö´ÐÐbash·´µ¯shellÏÂÁîÓÐÎóʱ£¬»á·µ»Øbash:nojobcontrolinthisshell
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-YamlDotNetʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_yii·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPʹÓÃÄ¿µÄipÉÏyiiµÄ·´ÐòÁл¯Îó²î½á¹¹ÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌÏÂÁîÖ´ÐеÄÐÐΪ¡£YiiÊÇÒ»¸ö¸ßÐÔÄܵÄPHP5µÄwebÓ¦ÓóÌÐò¿ª·¢¿ò¼Ü¡£Í¨¹ýÒ»¸ö¼òÆÓµÄÏÂÁîÐй¤¾ßyiic¿ÉÒÔ¿ìËÙ½¨ÉèÒ»¸öwebÓ¦ÓóÌÐòµÄ´úÂë¿ò¼Ü£¬¿ª·¢Õß¿ÉÒÔÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÌí¼ÓÓªÒµÂß¼£¬ÒÔ¿ìËÙÍê³ÉÓ¦ÓóÌÐòµÄ¿ª·¢¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_ZendFramework_3.0_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2021-3007][CNNVD-202101-025]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPʹÓÃÄ¿µÄipÉÏZendFramework3.0µÄ·´ÐòÁл¯Îó²î½á¹¹ÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌÏÂÁîÖ´ÐеÄÐÐΪ¡£ZENDZendFramework£¨ZF£©ÊÇÃÀ¹úZend£¨ZEND£©¹«Ë¾µÄÒ»Ì׿ªÔ´µÄPHP¿ª·¢¿ò¼Ü£¬ËüÖ÷ÒªÓÃÓÚ¿ª·¢Web³ÌÐòºÍ·þÎñ¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_Swagger-api¹¤¾ß_Ãô¸ÐÎļþ»á¼û
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢»ùÓÚYAML¡¢JSONÓïÑÔµÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£©£¬Ïà¹ØÎļþ¼Ð±»»á¼ûÓÐÐÅϢй¶Σº¦¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£
¸üÐÂʱ¼ä£º 20221122