2020-11-10

Ðû²¼Ê±¼ä 2020-11-10
ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_ľÂí_Downloader.APT-C-23_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½ APT-C-23ÏÂÔØÆ÷ľÂí ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË APT-C-23ÏÂÔØÆ÷ľÂí¡£APT-C-23ÏÂÔØÆ÷ľÂí ÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20201110


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Nagios_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-20197]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

NagiosÊÇÒ»¿î¿ªÔ´µÄµçÄÔϵͳºÍÍøÂç¼àÊÓ¹¤¾ß£¬ÄÜÓÐЧ¼à¿ØWindows¡¢LinuxºÍUnixµÄÖ÷»ú״̬£¬½»»»»ú·ÓÉÆ÷µÈÍøÂçÉèÖ㬴òÓ¡»úµÈ¡£ÔÚϵͳ»ò·þÎñ״̬Ò쳣ʱ·¢³öÓʼþ»ò¶ÌÐű¨¾¯µÚһʱ¼ä֪ͨÍøÕ¾ÔËάÈËÔ±£¬ÔÚ״̬»Ö¸´ºó·¢³öÕý³£µÄÓʼþ»ò¶ÌÐÅ֪ͨ¡£ÔÚNagios XI 5.6.9°æ±¾ÖУ¬NagiosµÄ¡°³ÂËß¡±Ä£¿é´æÔÚ©¶´£¬¹¥»÷Õß¿Éͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊýÀûÓø鶴ִÐÐÈÎÒâµÄ²Ù×÷ϵͳÃüÁî¡£

¸üÐÂʱ¼ä£º

20201110


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Nodejs´úÂë×¢È멶´[CVE-2020-7699][CNNVD-202007-1739]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¸Ã©¶´Î»ÓÚexpress-fileupload npm×é¼þÖУ¬¸Ã×é¼þ´Ónpm´¦ÏÂÔØÁ¿Áè¼Ý730Íò£¬ÆäÖв»º¬ÓдÓGitHub¡¢¾µÏñÍøÕ¾ºÍÆäËû¿Ë¡¿âÖÐÏÂÔصÄ¡£¸Ã©¶´ÊôÓÚPrototype Pollution£¨Ô­ÐÍÎÛȾ£©Â©¶´ÀàÐÍ£¬ÕâÊÇJS´úÂëÖеij£¼û©¶´ÀàÐÍ¡£ÒòΪJSÊÇ»ùÓÚÔ­Ð͵ÄÓïÑÔ£¬ÓïÑÔÖеÄÿ¸ö¹¤¾ß¡¢º¯ÊýºÍÊý¾Ý½á¹¹¶¼ÓÐPrototypeÌØÕ÷£¬¿ÉÒÔͨ¹ý"_proto__"½øÐÐÐ޸ġ£Ê¹ÓÃÕâÖÖÉè¼Æ©¶´µÄÔ­Ð͹¥»÷ͨ¹ý×¢Èë²»ÏàÊÊÓ¦µÄ¹¤¾ßÀàÐ͵½ÏÖÓеŤ¾ßÖÐÀ´Òý·¢´íÎó£¬ÆæÈȵ¼ÖÂDoS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20201110


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ApacheKylin_ÃüÁî×¢È멶´[CVE-2020-1956][CNNVD-202005-1133]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Apache Kylin ÊÇÃÀ¹úApache Èí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÂþÑÜʽ·ÖÎöÐÍÊý¾Ý¶ÑÕ»¡£¸Ã²úÎïÖ÷ÒªÌṩ Hadoop/Spark Ö®É쵀 SQL ²éѯ½Ó¿Ú¼°¶àά·ÖÎö£¨OLAP£©µÈ¹¦Ð§¡£

¸üÐÂʱ¼ä£º

20201110


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_XXL_JOB_δÊÚȨ·ÃÎÊÔ¶³ÌÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

XXL-JOBÊÇÒ»¸öÇáÁ¿¼¶ÂþÑÜʽÈÎÎñµ÷ÖÎƽ̨¡£Ä¬ÈÏÇé¿öÏÂXXL-JOBµÄRestful API½Ó¿Ú»òRPC½Ó¿ÚûÓÐÅäÖÃÈÏÖ¤´ëÊ©£¬Î´ÊÚȨµÄ¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇó£¬Ôì³ÉÔ¶³ÌÖ´ÐÐÃüÁֱ½Ó¿ØÖÆ·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20201110


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-14882][CVE-2020-14750]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóÀûÓø鶴£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܽӹÜOracle WebLogic Server¡£

¸üÐÂʱ¼ä£º

20201110


ʼþÃû³Æ£º

HTTP_WebLogic_XXE×¢È멶´[CVE-2019-2887]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWebLogic_XXE×¢È멶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£WebLogic_XXE×¢È멶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ЭÒé¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷,ÈÎÒâÎļþ¶ÁÈ¡£¬»ñÈ¡ÍøÕ¾µÄÃô¸ÐÊý¾ÝµÈ¡£

¸üÐÂʱ¼ä£º

20201110


ʼþÃû³Æ£º

HTTP_WebLogic_Blind_XXE×¢È멶´[CVE-2019-2647]

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWebLogic_Blind_XXE×¢È멶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£WebLogic_Blind_XXE×¢È멶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3ЭÒéÖУ¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload½øÐз´ÐòÁл¯£¬´Ó¶øʵÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷¡£

¸üÐÂʱ¼ä£º

20201110


ʼþÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÇëÇó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£

¸üÐÂʱ¼ä£º

20201110