ÿÖÜÉý¼¶²¼¸æ-2021-11-23
°ä²¼¹¦·ò 2021-12-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_F5_BIG_IP_TMM_»º³åÇøÒç³ö·ì϶[CVE-2021-22991][CNNVD-202103-784] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | F5BIG-IPÊÇÃÀ¹úF5¹«Ë¾µÄÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿ÖÎÀí¡¢ÀûÓ÷¨Ê½°²È«ÖÎÀí¡¢¸ºÔØÆ½ºâ¡¢DDoS·ÀÓùµÈÖ°ÄܵÄÀûÓý»¸¶Æ½Ì¨¡£¡£¡£F5BIG-IP´æÔÚ°²È«·ì϶£¬£¬£¬Á÷Á¿ÖÎÀí΢ÄÚºË(TrafficManagementMicrokernel,TMM)URIµÄ¹æ·¶»¯¿ÉÄÜ»áÃýÎ󵨴¦ÖöÔÐé¹¹·þÎñÆ÷µÄÒªÇ󣬣¬£¬´Ó¶ø´¥·¢»º³åÇøÒç³ö£¬£¬£¬µ¼Ö»ؾø·þÎñ¹¥»÷¡£¡£¡£Ôڿ϶¨Ç°ÌáÏ£¬£¬£¬¿ÉÄÜÈÆ¹ý»ùÓÚURLµÄ½Ó¼û½ÚÖÆ£¬£¬£¬Ôì³ÉÔ¶³ÌºÅÁîÖ´ÐС£¡£¡£¸Ã·ì϶ͨ¹ý¹¹½¨ÀàËÆHTTPµÄÒªÇó´¥·¢ºÅÁîÖ´ÐС£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_XSSƽ̨¶ñÒâ´úÂëÖ²Èë |
°²È«ÀàÐÍ£º | ÆäËû×¢Èë |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ö÷ÕÅIPÖ÷»úÒ³Ãæ±»Ö²ÈëXSSƽ̨µÄ¶ñÒâhtml´úÂë¡£¡£¡£XSSÓÖ½ÐCSS(CrossSiteScript)£¬£¬£¬¿çÕ¾¾ç±¾¹¥»÷¡£¡£¡£ËüÖ¸µÄÊǶñÒâ¹¥»÷ÕßÍùWebÒ³ÃæÀï²åÈë¶ñÒâhtml´úÂ룬£¬£¬µ±Óû§ä¯ÀÀ¸Ãҳ֮ʱ£¬£¬£¬Ç¶ÈëÆäÖÐWebÀïÃæµÄhtml´úÂë»á±»Ö´ÐУ¬£¬£¬´Ó¶ø´ïµ½¶ñÒâÓû§µÄÌØÊâÖ÷ÕÅ£¬£¬£¬Èç»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£XSSƽ̨ÔòÊÇÓÃÀ´·ºÖ¸½Ó¹Ü¶ñÒâXSS¹¥»÷»ñÈ¡µÄÃô¸ÐÐÅÏ¢µÄÒ»ÖÖÆ½Ì¨£¬£¬£¬Í¨³£ÓµÓÐÄ£¿£¿é»¯µÄXSSpayload£¬£¬£¬Í¨¹ý½«ÆäÖ²ÈëÓû§ä¯ÀÀÆ÷£¬£¬£¬½ÚÖÆÊܺ¦Õßä¯ÀÀÆ÷Ïòƽ̨·¢ËÍÃô¸ÐÐÅÏ¢²¢¼Í¼¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Apache_Solr<=8.8.2_ËÁÒâÎļþɾ³ý·ì϶ |
°²È«ÀàÐÍ£º | ÆäËû¹¥»÷ÀûÓà |
ÊÂÎñÃèÊö£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚÀûÓÃApacheSolr<=8.8.2ËÁÒâÎļþɾ³ý·ì϶¡£¡£¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶»ú¹Ø¶ñÒâµÄrequesthandler£¬£¬£¬½Ó¼ûÌØ¶¨urlºó¿É´¥·¢É¾³ýÊܺ¦IPÖ÷»úÉϵÄËÁÒâÖ¸¶¨Îļþ¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_VoIPmonitor_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2021-30461][CNNVD-202105-1992] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | VoIPmonitorÊÇ¡°ÓµÓÐÔÚLinuxÉÏÔËÐеÄSIPRTPºÍRTCPVoIPºÍ̸µÄÓµÓÐóÒ×ǽ˵ĿªÔ´ÍøÂçÊý¾Ý°üÐá̽Æ÷¡±¡£¡£¡£VoIPmonitorWeb½çÃæ£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÓû§´¥·¢VoIPmonitorÖеÄÔ¶³ÌPHP´úÂëÖ´Ðзì϶¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Workreap_ÎļþÉÏ´«·ì϶[CVE-2021-24499] |
°²È«ÀàÐÍ£º | ÎļþÉÏ´« |
ÊÂÎñÃèÊö£º | AmentotechWorkreap<2.2.2°æ±¾´æÔÚÒ»¸öδ¾Éí·ÝÑéÖ¤ËÁÒâÎļþÉÏ´«·ì϶£¬£¬£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¸Ã·ì϶ԴÓÚ`workreap_award_temp_file_uploader`ºÍ`workreap_temp_file_uploader`ûÓÐÖ´ÐÐnonce²é³£¬£¬£¬»òÒÔÈÎºÎÆäËû·½Ê½ÑéÖ¤ÒªÇóÊÇ·ñÀ´×ÔÓÐЧÓû§£¬£¬£¬ÔÊÐí½«ËÁÒâÎļþÉÏ´«µ½uploads/workreap-tempĿ¼¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ÏÂÔØÕßľÂí |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬£¬£¬ÔËÐк󣬣¬£¬Äܹ»ÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬£¬ÈçºóÃŵȡ£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_·ºÎ¢OA_eoffice8_ËÁÒâÎļþÉÏ´«·ì϶ |
°²È«ÀàÐÍ£º | ÎļþÉÏ´« |
ÊÂÎñÃèÊö£º | ·ºÎ¢OA-eoffice8ϵͳ´æÔÚǰ̨ËÁÒâÎļþÉÏ´«·ì϶£¬£¬£¬Í¨¹ý´Ë·ì϶¹¥»÷Õß¿ÉÉÏ´«ËÁÒâphpÌåʽÎļþ£¬£¬£¬ºó¶Ë·þÎñÆ÷»á³É¹¦½âÎö¸ÃÎļþ£¬£¬£¬µ¼Ö¿Éͨ¹ý´Ë·ì϶ֱ½Ó»ñȡϵͳȨÏÞ¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_SonarQube_δÊÚȨ½Ó¼û·ì϶[CVE-2020-27986][CNNVD-202010-1588] |
°²È«ÀàÐÍ£º | Ãô¸ÐÐÅϢй¶ |
ÊÂÎñÃèÊö£º | SonarQubeÊÇÈðÊ¿SonarSource¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ´úÂëÖÊÁ¿ÖÎÀíϵͳ¡£¡£¡£SonarQube8.4.2.36762°æ±¾´æÔÚ°²È«·ì϶£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýapi/settings/values·¢ÏÖÃ÷ÎÄSMTP¡¢SVNºÍGitLabÍ´´¦¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_"font-family:ËÎÌå">¿ÉÒÉwebshell |
°²È«ÀàÐÍ£º | ÎļþÉÏ´« |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÕýÔÚÉÏ´«¿ÉÒÉ"font-family:ËÎÌå">µÄwebshellÎļþ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_Win32.Echelon_Stealer_ÏνÓC2·þÎñÆ÷_ÉÏ´«ÇÔÃÜÐÅÏ¢ |
°²È«ÀàÐÍ£º | ÇÔÃÜľÂí |
ÊÂÎñÃèÊö£º | Echelon_StealerÊÇÒ»¸öÇÔÃÜľÂí£¬£¬£¬Ê¹ÓÃC#˵»°±àд¶ø³É¡£¡£¡£EchelonStealerµÄ×÷ÕßÊÇÒ»¸öÃûΪ¡°Madcode¡±µÄÍøÂçÆ×Ó¡£¡£¡£EchelonStealerÔÚGitHubƽ̨ÉϹ«¿ª°ä²¼¡£¡£¡£EchelonStealerµÄÖØÒªÖ¸±êÊÇ´ÓÆäÖ¸±ê»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬ÒԵǼʹ´¦¡¢Ð¡ÎÒ¶Ô»°¡¢¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡¢Ãô¸ÐÎļþµÈΪָ±ê¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÒªÇó3 |
°²È«ÀàÐÍ£º | ÍÚ¿óÈí¼þ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½ÍÚ¿óľÂíÊÔͼÏνÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£ÍÚ¿óľÂí³¢ÊÔÏÎ½Ó¿ó³Ø£¬£¬£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬£¬£¬¿÷ËðCPU×ÊÔ´¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ThinkPHP5.0.x-5.0.23Ô¶³Ì´úÂëÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP¿ò¼ÜÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ£¬£¬£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬£¬£¬ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£¡£¡£ThinkPHPÊÇÒ»¸öÊ¢ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£¡£¡£µ±WebÍøÕ¾ÊÇ»ùÓÚThinkPHP¿ò¼Ü¿ª·¢Ê±£¬£¬£¬¿ÉÄÜ´æÔڸ÷ì϶ʱ¡£¡£¡£¹¥»÷Õß·¢Ë;«ÐÄ»ú¹ØµÄPHP´úÂëÔÚÖ¸±êÖ÷»úÉÏÖ´ÐУ¬£¬£¬Ì°Í¼½øÒ»²½½ÚÀñ·þÎñÆ÷¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃÊÂÎñ_·¢ÏÖʹÓÃunicode±àÂë |
°²È«ÀàÐÍ£º | ÆäËû¿ÉÒÉÐÐΪ |
ÊÂÎñÃèÊö£º | JavaĬÈϵıàÂ뷽ʽΪUnicode£¬£¬£¬ÔÚjava˵»°ºÍ²¿ÃÅ.net·¨Ê½ÖУ¬£¬£¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_D-Link-HNAP-SoapAction-HeaderºÅÁîÖ´Ðзì϶[CVE-2015-2051] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | D-LinkDIR-645Wired/WirelessRouterÊÇÓÑѶ(D-Link)¹«Ë¾µÄÒ»¿îÖÇÄÜÎÞÏß·ÓÉÆ÷²úÆ·¡£¡£¡£Ê¹ÓÃ1.04b12¼°Ö®Ç°°æ±¾¹Ì¼þµÄD-LinkDIR-645ÖдæÔÚ°²È«·ì϶£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý¶ÔHNAP½Ó¿ÚÖ´ÐÐGetDeviceSettings²Ù×÷£¬£¬£¬ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Thinkphp3.2.x_ÎļþÔ̺¬·ì϶ |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | PHPUnitÊÇPHP³Ìʽ˵»°ÖÐ×î³£¼ûµÄµ¥Ôª²âÊÔ(unittesting)¿ò¼Ü£¬£¬£¬Í¨³£phpunitʹÓÃcomposer¼«¶ÈÊ¢ÐеÄPHPÒÀÀµÖÎÀíÆ÷½øÐв¿Êð,½«»áÔÚµ±Ç°Ä¿Â¼´´½¨Ò»¸övendorÎļþ¼Ð.phpunit³ö²ú»·¾³ÖÐÒÀÈ»×°ÖÃÁËËü,ÈôÊǸñàдÆ÷Ä£¿£¿é´æÔÚÓÚWeb¿É½Ó¼ûĿ¼£¬£¬£¬Ôò´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÒªÇó2 |
°²È«ÀàÐÍ£º | ÍÚ¿óÈí¼þ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½ÍÚ¿óľÂíÊÔͼÏνÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£ÍÚ¿óľÂí³¢ÊÔÏÎ½Ó¿ó³Ø£¬£¬£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬£¬£¬¿÷ËðCPU×ÊÔ´¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |
ÊÂÎñÃû³Æ£º | HTTP_Jenkins-Groovy-Sandbox-breakout_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½HTTP_Jenkins-Groovy-Sandbox-breakout_Ô¶³Ì´úÂëÖ´Ðй¥»÷¡£¡£¡£groovyɳÏ䣬£¬£¬±àÒ빦·òת»»Æ÷ÔÚÏÞ¶ÈÐÔɳÏäÖÐÔËÐÐGroovy´úÂë¡£¡£¡£°²È«Ö´Ðв»ÊÜÐÅÀµµÄ¾ç±¾¡£¡£¡£´Ë·ìÏ¶ÈÆ¹ýÁËJenkinsµÄGroovyɳÏ䣬£¬£¬µ¼ÖÂÁË´úÂëÖ´ÐС£¡£¡£¹¥»÷³É¹¦£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ |
¸üй¦·ò£º | 20211123 |


¾©¹«Íø°²±¸11010802024551ºÅ