2020-09-16

Ðû²¼Ê±¼ä 2020-09-17

ÐÂÔöʼþ



ʼþÃû³Æ£º

TCP_Äþ¾²Â©¶´_Microsoft_NetLogon_ÌØȨÌáÉý©¶´[CVE-2020-1472][CNNVD-202008-548]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¹¥»÷ÕßʹÓà Netlogon Ô¶³ÌЭÒé (MS-NRPC) ½¨Á¢ÓëÓò¿ØÖÆÆ÷Á¬½ÓµÄ Netlogon Äþ¾²Í¨µÀʱ£¬´æÔÚÌØȨÌáÉý©¶´¡£µ±ÀÖ³ÉÀûÓôË©¶´Ê±£¬¹¥»÷ÕßÎÞÐèͨ¹ýÉí·ÝÑéÖ¤£¬¼´¿ÉÔÚÍøÂçÖеÄÉ豸ÉÏÔËÐо­ÌØÊâÉè¼ÆµÄÓ¦Ó÷¨Ê½£¬»ñÈ¡Óò¿ØÖÆÆ÷µÄ¹ÜÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20200916


ʼþÃû³Æ£º

TCP_Java·´ÐòÁл¯_Clojure_ÀûÓÃÁ´¹¥»÷

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃClojureµÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ.ClojureÊÇÒ»ÖÖLISP·ç¸ñµÄÓïÑÔ£¬ÔËÐÐÔÚJVMÉÏ¡£ClojureµÄÒ»´óÌØÉ«¾ÍÊÇÆä²¢·¢»úÖÆ£¬ËüÖ§³Ö²»ÐбäµÄÊý¾Ý½á¹¹£¨ClojureÊÇÀ´×ÔÓڿɳ־û¯µÄÊý¾Ý½á¹¹£©¡£Clojure»¹ÓÐÒ»¸öÌØÉ«ÊÇÈí¼þÊÂÎñ´æ´¢£¨Software Transactional Memory£¬STM£©£¬ÆäÖ§³ÖÓÃÊÂÎñÈ¡´úËøºÍ»¥³âÆ÷À´¸üй²ÏíÄÚ´æ¡£STM»¹ÊÇÒ»¸öÓÐÕùÒéµÄ¼¼Êõ£¬»¹ÐèÒª¸üºÃµÄÖ¤Ã÷×Ô¼º£¬Ò»¸ö¼òµ¥µÄ´ëÊ©¾ÍÊÇ·ÃÎÊÒ»¸öJVMÉϵÄʵÏÖ¡£

¸üÐÂʱ¼ä£º

20200916


ʼþÃû³Æ£º

HTTP_ͨ´ïOA_Îļþɾ³ýµ¼ÖµÄÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃͨ´ïOAµÄV11.6°æ±¾µÄÎļþɾ³ý©¶´½øÐй¥»÷¡£

¸üÐÂʱ¼ä£º

20200916


ʼþÃû³Æ£º

TCP_Java·´ÐòÁл¯_C3P0_ÀûÓÃÁ´¹¥»÷

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃC3P0µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£C3P0ÊÇÒ»¸ö¿ªÔ´µÄJDBCÁ¬½Ó³Ø£¬ËüʵÏÖÁËÊý¾ÝÔ´ºÍJNDI°ó¶¨£¬Ö§³ÖJDBC3¹æ·¶ºÍJDBC2µÄ³ß¶ÈÀ©Õ¹¡£Ä¿Ç°Ê¹ÓÃËüµÄ¿ªÔ´ÏîÄ¿ÓÐHibernate¡¢SpringµÈ¡£

¸üÐÂʱ¼ä£º

20200916


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_PHPCMS_v9_swfupload_json_SQL×¢È멶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓà PHPCMS v9 swfupload_json SQL×¢È멶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐĽṹµÄ¹¥»÷payload»ñÈ¡ÍøÕ¾Êý¾Ý¿âÃô¸ÐÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20200916


ʼþÃû³Æ£º

TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-2551]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-2551£©£¬Oracle WebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-2551£©£¬ÊÔͼͨ¹ýGIOPЭÒé´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£Â©¶´´æÔÚµÄweblogic°æ±¾:10.3.6.0.012.1.3.0.012.2.1.3.012.2.1.4.0Èç¹û±»¹¥»÷»úÆ÷ûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡£¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£ÊµÑé½øÐжñÒâÃüÁî»ò´úÂë×¢È룬Զ³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20200916


ʼþÃû³Æ£º

TCP_Java·´ÐòÁл¯_ROME_ÀûÓÃÁ´¹¥»÷

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃROMEµÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200916


ʼþÃû³Æ£º

HTTP_ZeroShell_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2019-12725]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ZeroshellÊÇÒ»Ì×ÃæÏò·þÎñÆ÷ºÍǶÈëʽϵͳµÄLinux¿¯Ðаæ¡£Zeroshell 3.9.0°æ±¾ÖдæÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÕýÈ·´¦ÖÃHTTP²ÎÊý¡£

¸üÐÂʱ¼ä£º

20200916


ʼþÃû³Æ£º

HTTP_ÉÏ´«¼ÓÃÜASP_Webshell

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPµØÖ·Ö÷»úÕýÔÚÏòÄ¿µÄIPµØÖ·Ö÷»ú´«ËÍ¿ÉÒɵļÓÃÜwebshellÎļþ¡£

¸üÐÂʱ¼ä£º

20200916