ÿÖÜÉý¼¶²¼¸æ-2022-11-22

°ä²¼¹¦·ò 2022-11-22
ÐÂÔöÊÂÎñ



ÊÂÎñÃû³Æ£º£º    TCP_ºóÃÅ_Beacon.Payload_ÏνÓ
°²È«ÀàÐÍ£º£º    Ä¾ÂíºóÃÅ
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ö÷ÕÅIPÖ÷»úÊÔͼÏòÔ´IPÖ÷»ú´«ÊäºóÃÅ¡£³£¼ûµÄBeaconÔ̺¬CobaltStrikeµÄBeacon£¬£¬£¬ÒÔ¼°MetasploitµÄMeterpreterµÈ¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_Îļþ²Ù×÷¹¥»÷_Apache_Flink_СÓÚ1.11.2_ËÁÒâÎļþ¶ÁÈ¡[CVE-2020-17519][CNNVD-202101-271]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ApacheFlink1.11.0,1.11.1,1.11.2°æ±¾ÔÊÐí¹¥»÷Õßͨ¹ýJobManager¹ý³ÌµÄRESTAPI¶ÁÈ¡JobManager±¾µØÎļþϵͳÉϵÄÈκÎÎļþ£¨JobManager¹ý³ÌÄܽӼûµ½µÄ£©¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÐÅϢй¶_SQLiteManager_1.2.0_Ŀ¼´©Ô½[CVE-2007-1232]
°²È«ÀàÐÍ£º£º    CGI¹¥»÷
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃSQLiteManagerµÄĿ¼´©Ô½·ì϶½Ó¼ûÃô¸ÐÎļþ¡£SQLiteManager1.2.0°æ±¾ÖеÄĿ¼±éÀú·ì϶ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýSQLiteManager_currentThemeÖеÄ..¶ÁÈ¡ËÁÒâÎļþ¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÌáȨ¹¥»÷_Apache_CouchDB_JSON_ºÅÁîÖ´ÐÐ[CVE-2017-12636][CNNVD-201711-486]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úÉÏApacheCouchDBµÄRestfulµÄAPI½Ó¿Ú´æÔڵķì϶£¬£¬£¬»ú¹Ø¶ñÒâJsonÌåʽµÄÊý¾Ý£¬£¬£¬´Ó¶øÊ¹·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý½Ó¼û·þÎñÆ÷ÉϵÄËÁÒâshellºÅÁî¡£CouchDBÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢Ìåʽ£¬£¬£¬JavaScript×÷Ϊ²éÎÊ˵»°£¬£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£CouchDBѡȡ»ùÓÚErlangµÄJSON½âÎöÆ÷£¬£¬£¬Óë»ùÓÚJavaScriptµÄJSON½âÎöÆ÷·ÖÆç£¬£¬£¬CouchDBÄܹ»ÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇÉ«·´¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ½Ó¼û½ÚÖÆ£¬£¬£¬ÉõÖÁÔ̺¬°µÊ¾ÖÎÀíÓû§µÄ_admin½ÇÉ«¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÌáȨ¹¥»÷_ÖÂÔ¶OA_ajax.do_δÊÚȨ½Ó¼û
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÕýÔÚÀûÓÃÖÂÔ¶OAV8.0ÒÔϰ汾µÄδÊÚȨ·ì϶»ñȡȨÏÞÀ´½øÇ°½øÒ»²½ÎļþÉÏ´«µÄ¹¥»÷£»£»£»ÖÂÔ¶OA°ì¹«×Ô¶¯»¯Èí¼þ£¬£¬£¬ÓÃÓÚOA°ì¹«×Ô¶¯»¯Èí¼þµÄ¿ª·¢ÏúÊÛ¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_Îļþ²Ù×÷¹¥»÷_ÈôÒÀCMS_СÓÚ4.5.1_Îļþ¶ÁÈ¡[CNVD-2021-01931]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃÈôÒÀCMS<4.5.1°æ±¾ÖеÄËÁÒâÎļþ¶ÁÈ¡·ì϶£¬£¬£¬µÇ¼ºó¶Üºó£¬£¬£¬Äܹ»¶ÁÈ¡·þÎñÆ÷ÉϵÄËÁÒâÎļþ¡£ÈôÒÀÖÎÀíϵͳÊÇ»ùÓÚSpringBootµÄȨÏÞÖÎÀíϵͳ¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange_Servers_ºÅÁîÖ´ÐÐ[CVE-2022-40140][CVE-2022-41082]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ExchangeServerÊÇ΢Èí¹«Ë¾µÄÒ»Ì×µç×ÓÓʼþ·þÎñ×é¼þ,ÊǸöÐÂÎÅÓëºÏ×÷ϵͳ¡£¸Ãϵͳ´æÔÚ·ì϶£¬£¬£¬¿ÉÔÚ¾­¹ýExchangeServerÉí·ÝÑéÖ¤²¢ÇÒÓµÓÐPowerShell²Ù×÷ȨÏÞµÄÇé¿öÏÂÀûÓÃÕâЩ·ì϶£¨×éºÏÀûÓã©Ô¶³ÌÖ´ÐжñÒâ´úÂ룺£ºCVE-2022-41040£º£ºMicrosoftExchangeServer·þÎñÆ÷¶ËÒªÇóαÔì(SSRF)·ì϶£¬£¬£¬CVE-2022-41082£º£ºMicrosoftExchangeServerÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©·ì϶¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯Èƹý[CVE-2019-2725][CNNVD-201904-1251]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    OracleWebLogicServerÊÇOracleCorporationµ±Ç°¿ª·¢µÄJavaEEÀûÓ÷þÎñÆ÷¡£OracleWebLogicServer10.3.6.0.0¡¢¡¢¡¢OracleWebLogicServer12.1.3.0.0°æ±¾´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬¸Ã·ìÏ¶ÈÆ¹ýCVE-2019-2725²¹¶¡£¬£¬£¬·ì϶´æÔÚwls-wsatºÍbea_wls9_async_response×é¼þ£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄ¶ñÒâHTTPÒªÇ󣬣¬£¬»ñÈ¡·þÎñÆ÷ȨÏÞ£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    SMTP_ÇÔÃÜľÂí_Snake_Keylogger_ÉÏ´«ÇÔÃÜÐÅÏ¢
°²È«ÀàÐÍ£º£º    Ä¾ÂíºóÃÅ
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½SnakeKeyloggerÇÔÃÜľÂíÕýÔÚÏòÔ¶³Ì·þÎñÆ÷ÉÏ´«ÇÔÃܵĸ÷ÀàÐÅÏ¢¡£Snake¶ñÒâÈí¼þÊÇÒ»ÖÖÒÔ.NET±à³Ì˵»°ÊµÏÖµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£Í¨¹ýÍøÂç´¹µöÓʼþ·Ö·¢¡£SnakeÊÇÒ»ÖÖÖ°ÄÜ·á˶µÄ¶ñÒâÈí¼þ£¬£¬£¬¶ÔÓû§µÄÒþÖԺͰ²È«×é³ÉÖØ´óÍþв¡£SnakeÓµÓмͼ»÷¼üÒÔ¼°¼ôÌù°åÊý¾Ý¡¢¡¢¡¢ÆÁÄ»½ØÍ¼ºÍÍ´´¦ÍµÇÔÖ°ÄÜ¡£SnakeÄܹ»´Ó50¶à¸öÀûÓ÷¨Ê½ÖÐÇÔȡʹ´¦£¬£¬£¬ÆäÖÐÔ̺¬FTP¿Í»§¶Ë¡¢¡¢¡¢Óʼþ¿Í»§¶Ë¡¢¡¢¡¢Í¨Ñ¶Æ½Ì¨ºÍWebä¯ÀÀÆ÷µÈÀûÓ÷¨Ê½¡£SnakeÖ§³Öͨ¹ý¶àÖÖºÍ̸½øÐÐÉÏ´«Êý¾Ý£¬£¬£¬ÀýÈçFTP¡¢¡¢¡¢SMTPºÍTelegramÈýÖÖ·½Ê½ÉÏ´«ÇÔÈ¡µÄÐÅÏ¢¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_fileDownload.jsp_ÎļþÏÂÔØ
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úÉϵķºÎ¢OAfileDownload.jsp´æÔÚµÄËÁÒâÎļþÏÂÔØ·ì϶¡£¹¥»÷ÕßÄܹ»Í¨¹ý..\/À´Èƹý·ºÎ¢¶Ô../µÄÏÞ¶È£¬£¬£¬´Ó¶øÊµÏÖËÁÒâÎļþÏÂÔØ¡£·ºÎ¢OAÊǹúÄÚ¹«Ë¾°ä²¼µÄÒ»¿îÒÆ¶¯°ìƽÕý̨¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_Ecology_weaver.eui.EuiServlet_ÎļþÉÏ´«
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÖ÷ÕÅÖ÷»úÉϵķºÎ¢OA_EcologyÉϺó¶Ü´æÔÚµÄÎļþÉÏ´«·ì϶ÉÏ´«ËÁÒâÎļþ£¬£¬£¬´Ó¶ø»ñȡȨÏÞ¡£·ºÎ¢OAÊǹúÄÚ¹«Ë¾°ä²¼µÄÒ»¿îÒÆ¶¯°ìƽÕý̨¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÌáȨ¹¥»÷_Apache_Spark_´úÂëÖ´ÐÐ[CVE-2020-9480]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ApacheSparkÊÇÒ»¸ö¿ªÔ´¼¯ÈºÔËËã¿ò¼Ü¡£ÔÚApacheSpark2.4.5ÒÔ¼°¸üÔç°æ±¾ÖÐSparkµÄÈÏÖ¤»úÖÆ´æÔÚȱµã£¬£¬£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¹¥»÷ÕßÀûÓø÷ì϶£¬£¬£¬¿ÉÔÚδÊÚȨµÄÇé¿öÏ£¬£¬£¬ÔÚÖ÷»úÉÏÖ´ÐкÅÁ£¬£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐС£
¸üй¦·ò£º£º    20221122



Åú¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º£º    TCP_ºóÃÅ_Yakes.qwqÏνÓ
°²È«ÀàÐÍ£º£º    ÆäËûÊÂÎñ
ÊÂÎñÃèÊö£º£º    ¸ÃÊÂÎñÅú×¢£¬£¬£¬Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¸ÃÊÂÎñÔ´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅYakes.qwq¡£Yakes.qwqÊÇ»ùÓÚIRCºÍ̸µÄºóÃÅ£¬£¬£¬ÔËÐк󣬣¬£¬°Ñ×ÔÉí´úÂë²åÈ뵽ϵͳÕý³£¹ý³Ì¡£ÏνÓÔ¶³ÌIRCºÅÁîºÍ½ÚÀñ·þÎñÆ÷£¬£¬£¬½Ó¹ÜÆäÖ¸Á£¬£¬²¢Ö´ÐС£ÈçÏÂÔØ¶ñÒâÈí¼þ£¬£¬£¬ÌáÒéDDOS¹¥»÷¡£±¾ºóÃÅÔËÐк󣬣¬£¬Æð³õ´´½¨¼Ù»ØÊÕÕ¾Îļþ¼Ð£¬£¬£¬²¢¿½±´×ÔÉíµ½¸ÃÎļþ¼ÐÏ£¬£¬£¬´ïµ½°µ²ØµÄÖ÷ÕÅ¡£ÉèÖÃ×¢²á±í£¬£¬£¬ÊµÏÖ¿ª»úÆô¶¯°µ²ØÔÚ¼Ù»ØÊÕÕ¾ÀïµÄºóÃÅ·¨Ê½¡£½Ó¹Ü²¢Ö´ÐÐIRC·þÎñÆ÷µÄÖ¸Áî¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ľÂíºóÃÅ_webshell_Altman_PHPÏνÓ
°²È«ÀàÐÍ£º£º    Ä¾ÂíºóÃÅ
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýWebshellÖÎÀí¹¤¾ßAltman½Ó¼ûÖ÷ÕÅÖ÷»úÉϵÄÒ»¾ä»°Webshell£¬£¬£¬´Ó¶øµÃµ½Ö´ÐдúÂë¡¢¡¢¡¢ÉÏ´«ÏÂÔØÎļþµÈȨÏÞ¡£Altman»ùÓÚ.Net4.0¿ª·¢£¬£¬£¬Õû¸ö·¨Ê½Ñ¡È¡mef²å¼þ¼Ü¹¹¡£Ä¿Ç°ÊµÏÖµÄÖ°ÄÜÓУº£ºShellÖÎÀí¡¢¡¢¡¢ºÅÁîÖ´ÐС¢¡¢¡¢ÎļþÖÎÀí¡¢¡¢¡¢Êý¾Ý¿âÖÎÀí¡¢¡¢¡¢±àÂëÆ÷µÈ£¬£¬£¬¾ç±¾ÀàÐÍÖ§³Öasp¡¢¡¢¡¢aspx¡¢¡¢¡¢php¡¢¡¢¡¢jsp¡¢¡¢¡¢python¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_Îļþ²Ù×÷¹¥»÷_Snews_CMS_ÎļþÉÏ´«¹¥»÷
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃSnewsCMSÖеÄÎļþÉÏ´«·ì϶£¬£¬£¬ÉÏ´«¶ñÒâÎļþ£¬£¬£¬´Ó¶ø»ñµÃÖ÷ÕÅIPÖ÷»úµÄÖ´ÐдúÂë¡¢¡¢¡¢ÎļþÉÏ´«¡¢¡¢¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£sNewsÊÇÒ»ÆëÈ«µØ×ÔÓɵġ¢¡¢¡¢Çкϳ߶ȵġ¢¡¢¡¢Ê¹ÓÃPHPºÍMySQLÇý¶¯µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_Îļþ²Ù×÷¹¥»÷_PHP_chrº¯Êý_webshellÎļþÉÏ´«
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃchrº¯Êý»ú¹Ø¶ñÒâÎļþÈÆ¹ý¹Ø¼ü´Ê¼ì²â£¬£¬£¬ÉÏ´«PHP¶ñÒâÎļþ£¬£¬£¬´Ó¶ø»ñµÃÖ÷ÕÅIPÖ÷»úµÄÖ´ÐдúÂë¡¢¡¢¡¢ÎļþÉÏ´«¡¢¡¢¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    TCP_ÌáȨ¹¥»÷_Zabbix_Server_trapper_ºÅÁîÖ´ÐÐ
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃZabbixµÄ·ì϶½øÐжñÒâºÅÁîÖ´ÐС£ZabbixÊÇÓÉAlexeiVladishev¿ª·¢µÄÒ»ÖÖÍøÂç¼à¶½¡¢¡¢¡¢ÖÎÀíϵͳ£¬£¬£¬»ùÓÚServer-Client¼Ü¹¹¡£ÔÚCVE-2017-2824ÖУ¬£¬£¬ÆäServer¶ËtrappercommandÖ°ÄÜ´æÔÚÒ»´¦´úÂëÖ´Ðзì϶£¬£¬£¬¶øÐÞ¸´²¹¶¡²¢²»ÃÀÂú£¬£¬£¬µ¼ÖÂÄܹ»ÀûÓÃIPv6½øÐÐÈÆ¹ý£¬£¬£¬×¢ÈëËÁÒâºÅÁî¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÐÅϢй¶_Alibaba_Canal-config_ÔÆÃÜÔ¿_ÐÅϢй¶
°²È«ÀàÐÍ£º£º    CGI¹¥»÷
ÊÂÎñÃèÊö£º£º    canalÊǰ¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌ⣬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄµØÖ·½Ó¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    TCP_ÌáȨ¹¥»÷_¿ÉÒÉ·´µ¯shellºÅÁî×¢Èë_¹¥»÷ʧ°Ü
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÖ÷ÕÅÖ÷»ú½øÐÐBASH_·´µ¯shellºÅÁî×¢Èë¹¥»÷¡£·´µ¯ÏνÓ£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨·þÎñ¶Ë£¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯Ïνӹ¥»÷ÕߵķþÎñ¶Ë·¨Ê½¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢¡¢¡¢È¨ÏÞ²»¼°¡¢¡¢¡¢¶Ë¿Ú±»Õ¼ÓõÈÇé¾°¡£¹¥»÷Õß¹¥»÷³É¹¦ºóÄܹ»Ô¶³ÌÖ´ÐÐϵͳºÅÁî¡£µ±Ö´ÐÐbash·´µ¯shellºÅÁîÓÐÎóʱ£¬£¬£¬»á·µ»Øbash:nojobcontrolinthisshell
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-YamlDotNetÀûÓÃÁ´_ysoserial¹¤¾ßÀûÓÃ_ºÅÁîÖ´ÐÐ
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢ÏÖµÄʵÓ÷¨Ê½ºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄ¼¯ÖУ¬£¬£¬Äܹ»ÔÚÊʵ±µÄǰÌáÏÂÀûÓÃ.NETÀûÓ÷¨Ê½Ö´Ðв»°²È«µÄ¶ÔÏó·´ÐòÁл¯¡£Ö÷Çý¶¯·¨Ê½½ÓÊÜÓû§Ö¸¶¨µÄºÅÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬¶øºó½«ÕâЩ¶ÔÏóÐòÁл¯µ½³ß¶ÈÊä³ö¡£µ±Ààõè¾¶ÉÏÓµÓÐËùÐèС¹¤¾ßµÄÀûÓ÷¨Ê½²»°²È«µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖºÅÁîÔÚÀûÓ÷¨Ê½Ö÷»úÉÏÖ´ÐС£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÌáȨ¹¥»÷_yii·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÀûÓÃÖ÷ÕÅipÉÏyiiµÄ·´ÐòÁл¯·ì϶»ú¹ØÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌºÅÁîÖ´ÐеÄÐÐΪ¡£YiiÊÇÒ»¸ö¸ß»úÄܵÄPHP5µÄwebÀûÓ÷¨Ê½¿ª·¢¿ò¼Ü¡£Í¨¹ýÒ»¸öµ¥Ò»µÄºÅÁîÐй¤¾ßyiicÄܹ»¼±¾ç´´½¨Ò»¸öwebÀûÓ÷¨Ê½µÄ´úÂë¿ò¼Ü£¬£¬£¬¿ª·¢ÕßÄܹ»ÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÔö³¤ÒµÎñÂß¼­£¬£¬£¬ÒÔ¼±¾çʵÏÖÀûÓ÷¨Ê½µÄ¿ª·¢¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÌáȨ¹¥»÷_ZendFramework_3.0_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2021-3007][CNNVD-202101-025]
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÀûÓÃÖ÷ÕÅipÉÏZendFramework3.0µÄ·´ÐòÁл¯·ì϶»ú¹ØÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌºÅÁîÖ´ÐеÄÐÐΪ¡£ZENDZendFramework£¨ZF£©ÊÇÃÀ¹úZend£¨ZEND£©¹«Ë¾µÄÒ»Ì׿ªÔ´µÄPHP¿ª·¢¿ò¼Ü£¬£¬£¬ËüÖØÒªÓÃÓÚ¿ª·¢Web·¨Ê½ºÍ·þÎñ¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_ÐÅϢй¶_Swagger-api¹¤¾ß_Ãô¸ÐÎļþ½Ó¼û
°²È«ÀàÐÍ£º£º    CGI¹¥»÷
ÊÂÎñÃèÊö£º£º    SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢¡¢¡¢»ùÓÚYAML¡¢¡¢¡¢JSON˵»°µÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢¡¢¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£º£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£©£¬£¬£¬ÓйØÎļþ¼Ð±»½Ó¼ûÓÐÐÅϢй¶·çÏÕ¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_°²È«·ì϶_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨºÅÁî×¢Èë
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬£¬exportovpn½Ó¿Ú´æÔÚºÅÁî×¢È룬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâºÅÁî¡£
¸üй¦·ò£º£º    20221122



ÊÂÎñÃû³Æ£º£º    HTTP_°²È«·ì϶_ÈôÒÀCMS_Ô¶³ÌºÅÁîÖ´Ðзì϶
°²È«ÀàÐÍ£º£º    °²È«·ì϶
ÊÂÎñÃèÊö£º£º    ÈôÒÀºó¶ÜÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬£¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄÌåʽ£¬£¬£¬¿ÉÓÃÓÚJava¶ÔÏóµÄÐòÁл¯¡¢¡¢¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºó¶Ü´òË㹤×÷´¦£¬£¬£¬¶ÔÓÚ´«ÈëµÄ"ŲÓÃÖ¸±ê×Ö·û´®"ûÓÐÈκÎУÑ飬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»»ú¹ØpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬£¬´Ó¶øÖ´ÐÐËÁÒâºÅÁî¡£
¸üй¦·ò£º£º    20221122