ÿÖÜÉý¼¶Í¨¸æ-2022-11-29

Ðû²¼Ê±¼ä 2022-11-29
ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º    HTTP_ÌáȨ¹¥»÷_Advantech_R-SeetNet_ÏÂÁîÖ´ÐÐ[CVE-2021-21805]
Çå¾²ÀàÐÍ£º    Çå¾²Îó²î
ÊÂÎñÐÎò£º    AdvantechR-SeeNetv2.4.12(20.10.2020)µÄping.php¾ç±¾¹¦Ð§Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£ÌØÖƵÄHTTPÇëÇó¿ÉÄܵ¼ÖÂí§Òâ²Ù×÷ϵͳÏÂÁîÖ´ÐС£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´´¥·¢´ËÎó²î¡£
¸üÐÂʱ¼ä£º    20221129


ÐÞ¸ÄÊÂÎñ

ÊÂÎñÃû³Æ£º    TCP_ÌáȨ¹¥»÷_Jackson_Databind_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-14379]
Çå¾²ÀàÐÍ£º    Çå¾²Îó²î
ÊÂÎñÐÎò£º    JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¹¥»÷Õß¿ÉÄÜʹÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààehcache¹¥»÷Ä¿µÄIPÖ÷»ú¡£
¸üÐÂʱ¼ä£º    20221129

ÊÂÎñÃû³Æ£º    TCP_Ãô¸ÐÐÅϢй¶_Linux_netstat_ÏÂÁîÖ´ÐлØÏÔ
Çå¾²ÀàÐÍ£º    CGI¹¥»÷
ÊÂÎñÐÎò£º    Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÏÂÁîµÄ»ØÏÔÐÅÏ¢£¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ£¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÏÂÁîµÄȨÏÞ¡£
¸üÐÂʱ¼ä£º    20221129

ÊÂÎñÃû³Æ£º    TCP_ÌáȨ¹¥»÷_java.lang.RuntimeÃô¸ÐÀà_´úÂëÖ´ÐÐ
Çå¾²ÀàÐÍ£º    Çå¾²Îó²î
ÊÂÎñÐÎò£º    ¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£ÔÚJavaÖУ¬³ÌÐò¿ª·¢Ö°Ô±Í¨³ £»áͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨Ö´ÐÐÍⲿµÄShellÏÂÁî¡£RuntimeÀàÊÇJava³ÌÐòµÄÔËÐÐʱÇéÐΣ¬¿ª·¢Õß¿ÉÒÔͨ¹ýgetRuntime()ÒªÁì»ñÈ¡Ä¿½ñRuntimeÔËÐÐʱ¹¤¾ßµÄÒýÓá£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬ÈôÊÇ´¦Öóͷ£ÍâÊÖÏÂÁîÖ´ÐÐʱ£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐÓõĹýÂË£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎó²îÔ¶³Ì×¢ÈëÏÂÁî»ò´úÂë²¢Ö´ÐС£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÒ»¾­±»Åû¶³ö±£´æJavaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õßͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐí§Òâ´úÂë»òÏÂÁ½øÒ»²½ÍêÈ«¿ØÖÆÄ¿µÄ·þÎñÆ÷¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
¸üÐÂʱ¼ä£º    20221129

ÊÂÎñÃû³Æ£º    HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë
Çå¾²ÀàÐÍ£º    Çå¾²Îó²î
ÊÂÎñÐÎò£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£
¸üÐÂʱ¼ä£º    20221129

ÊÂÎñÃû³Æ£º    HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î
Çå¾²ÀàÐÍ£º    Çå¾²Îó²î
ÊÂÎñÐÎò£º    ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£
¸üÐÂʱ¼ä£º    20221129