2021-01-19

Ðû²¼Ê±¼ä 2021-01-19

ÐÂÔöʼþ


ʼþÃû³Æ£º

TCP_ľÂí_CPUMiner_Á¬½Ó¿ó³ØÀÖ³É

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½µ½ÍÚ¿óľÂíCPUMinerÁ¬½Ó¿ó³ØÀֳɵÄÐÐΪ¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCPUMinerľÂí¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_Netis_WF2419_²Ù×÷ϵͳÃüÁî×¢È멶´[CVE-2019-19356][CNNVD-202002-238]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ʹÓÃV1.2.31805ºÍV2.2.36123°æ±¾¹Ì¼þµÄNetisWF2419ÖдæÔÚ²Ù×÷ϵͳÃüÁî×¢È멶´¡£¸Ã©¶´Ô´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÃüÁî¹ý³ÌÖУ¬ÍøÂçϵͳ»ò²úÎïδÕýÈ·¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÃüÁîµÈ¡£¹¥»÷Õß¿ÉÀûÓø鶴ִÐзǷ¨²Ù×÷ϵͳÃüÁî¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ZendFramework_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2021-3007][CNNVD-202101-025]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ZENDZendFramework£¨ZF£©ÊÇÃÀ¹úZend£¨ZEND£©¹«Ë¾µÄÒ»Ì׿ªÔ´µÄPHP¿ª·¢¿ò¼Ü£¬ËüÖ÷ÒªÓÃÓÚ¿ª·¢Web·¨Ê½ºÍ·þÎñ¡£ZendFramework3.0.0°æ±¾´æÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚÓÐÒ»¸ö·´ÐòÁл¯Â©¶´£¬¹¥»÷Õß¿ÉÀûÓø鶴Զ³Ì´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_ÎļþÉÏ´«_Apache_FlinkÈÎÒâÎļþÉÏ´«Â©¶´[CVE-2020-17518][CNNVD-202101-273]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃApache_Flink1.5.1½øÐÐÈÎÒâÎļþÉÏ´«;ApacheFlinkÊǾßÓÐÇ¿´óµÄÁ÷ºÍÅú´¦Öù¦Ð§µÄ¿ªÔ´Á÷´¦Öÿò¼Ü¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_Technicolor_TD5130_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-18396][CVE-2019-18396][CNNVD-201910-1908]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

TechnicolorTD5130v2ÊÇ·¨¹úÌØÒÕ£¨Technicolor£©¹«Ë¾µÄÒ»¿îµ÷Öƽâµ÷Æ÷¡£TechnicolorTD5130v2ÖеÄOiµÚÈý·½¹Ì¼þµÄPingÄ£¿é´æÔÚ²Ù×÷ϵͳÃüÁî×¢È멶´¡£¸Ã©¶´Ô´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÃüÁî¹ý³ÌÖУ¬ÍøÂçϵͳ»ò²úÎïδÕýÈ·¹ýÂËÆäÖеÄÌØÊâÔªËØ£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓø鶴ִÐзǷ¨ÃüÁî¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Schneider_Electric_U.Motion_BuilderÃüÁî×¢È멶´[CVE-2018-7841][CNNVD-201905-612]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

SchneiderElectricU.MotionBuilderÊÇ·¨¹úÊ©Ä͵µçÆø£¨SchneiderElectric£©¹«Ë¾µÄÒ»Ì×½¨ÖþÎïÖÇÄܹÜÀíϵͳ¡£SchneiderElectricU.MotionBuilder1.3.4¼°Ö®Ç°°æ±¾ÖеÄtrack_import_export.php½Å±¾ÖдæÔÚ²Ù×÷ϵͳÃüÁî×¢È멶´£¬¸Ã©¶´Ô´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÃüÁî¹ý³ÌÖУ¬ÍøÂçϵͳ»ò²úÎïδÕýÈ·¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÃüÁîµÈ¡£¹¥»÷Õß¿ÉÀûÓø鶴ִÐзǷ¨²Ù×÷ϵͳÃüÁî¡£

¸üÐÂʱ¼ä£º

20210119


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_Zabbix_JSON-RPC_Ô¶³ÌÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃZabbix_JSON-RPC_Ô¶³ÌÃüÁîÖ´ÐЩ¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£ZabbixÊÇÒ»¸ö¿ªÔ´µÄÆóÒµ¼¶ÐÔÄܼà¿Ø½â¾ö·½°¸¡£Zabbix°æ±¾2.2-3.0.3´æÔÚZabbix_JSON-RPC_Ô¶³ÌÃüÁîÖ´ÐЩ¶´£¬¹¥»÷ÕßÀûÓôË©¶´ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬Ô¶³ÌÖ´ÐÐϵͳÃüÁî¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_IBM_WebSphere_Java·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2015-7450]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

WebSphereÊÇIBM¹«Ë¾¿ª·¢µÄÖмä¼þ»ù´¡Éèʩƽ̨¡£WebSphere7°æ±¾ÔÚ¿ª·¢ÖÐʹÓÃÁËApacheCommonsCollections¿âÖеÄInvokerTransformerÀ࣬¸ÃÀà´æÔÚJava·´ÐòÁл¯Â©¶´¡£¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_Zabbix_JSON-RPC_Ô¶³ÌÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃNETGEAR_DGN2200_v1v2v3v4_Ô¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼͨ¹ýÔ¶³Ì´úÂëÖ´ÐЩ¶´ÈëÇÖNETGEAR·ÓÉÆ÷£¬¿ÉÒÔÖ´ÐÐÈÎÒâÃüÁî»ñµÃ·ÓÉÆ÷µÄ¿ØÖÆȨ¡£NETGEAR_DGN2200ÊÇÒ»¿î³£ÓõÄÎÞÏß·ÓÉÆ÷É豸¡£NETGEAR_DGN2200·ÓÉÆ÷µÄv1/v2/v3/v4°æ±¾´æÔÚdnslookup.cgiÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£µ±Ç°Â·ÓÉÆ÷¹Ì¼þΪÕâЩ°æ±¾Ê±´æÔڸ鶴£¬¹¥»÷Õß¿ÉÒÔͨ¹ý×Ô¶¯»¯½Å±¾¹¥»÷ÍøÂçÖеÄ·ÓÉÆ÷É豸£¬Ö´ÐÐÈÎÒâ´úÂ롣ʵÑéÔÚÄ¿±ê·ÓÉÆ÷É豸ÉÏÖ´ÐÐÈÎÒâ´úÂ룬¿ØÖÆÄ¿±ê·ÓÉÆ÷ÍøÂç¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_GPON_·ÓÉÆ÷_ÈÏÖ¤Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-3920][CNNVD-201903-080]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHTTP_GPON_·ÓÉÆ÷_ÈÏÖ¤Ô¶³ÌÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Liferay_Portal_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-7961][CNNVD-202003-1260]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

LiferayÊÇÒ»¸ö¿ªÔ´µÄPortal(ÈÏÖ¤)²úÎï,Ìṩ¶Ô¶à¸ö¶ÀÁ¢ÏµÍ³µÄÄÚÈݼ¯³É,ΪÆóÒµÐÅÏ¢¡¢Á÷³ÌµÈµÄÕûºÏÌṩÁËÒ»Ì×ÍêÕûµÄ½â¾ö·½°¸,ºÍÆäËûÉÌÒµ²úÎïÏà±È,LiferayÓÐןܶàÓÅÁ¼µÄÌØÐÔ,¶øÇÒÃâ·Ñ,ÔÚÈ«Çò¶¼Óн϶àÓû§¡£ÔÚLiferay6.1.x-7.2.x°æ±¾ÖдæÔÚͨ¹ýδÊÚȨ·ÃÎʵÄapi½á¹¹jsonÓï¾äµ¼Ö·´ÐòÁл¯Â©¶´½ø¶øÖ´Ðй¥»÷Õß´úÂëÃüÁîµÄ©¶´¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÖÂÔ¶OA_ajaxaction_ÎļþÉÏ´«Â©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÖÂÔ¶OAÊÇÒ»Ìװ칫ЭͬÈí¼þ¡£½üÈÕ£¬°¢ÀïÔÆÓ¦¼±ÏìÓ¦ÖÐÐļà¿Øµ½ÖÂÔ¶OAajaxActionÎļþÉÏ´«Â©¶´ÀûÓôúÂëÅû¶¡£ÓÉÓÚÖÂÔ¶OA¾É°æ±¾Ä³Ð©ajax½Ó¿Ú´æÔÚδÊÚȨ·ÃÎÊ£¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬿ÉÔÚÎÞÐèµÇ¼µÄÇé¿öÏÂÉÏ´«¶ñÒâ½Å±¾Îļþ£¬´Ó¶ø¿ØÖÆ·þÎñÆ÷¡£ÖÂÔ¶OA¹Ù·½ÒÑÕë¶Ô¸Ã©¶´Ìṩ²¹¶¡£¬¸Ã©¶´ÀûÓôúÂëÒÑÔÚ»¥ÁªÍøÉϹûÈ»Á÷´«¡£°¢ÀïÔÆÓ¦¼±ÏìÓ¦ÖÐÐÄÌáÐÑÖÂÔ¶OAÓû§¾¡¿ì½ÓÄÉÄþ¾²´ëÊ©×èֹ©¶´¹¥»÷¡£

¸üÐÂʱ¼ä£º

20210119


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÖÂÔ¶OA_δÊÚȨ·ÃÎÊ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÖÂÔ¶OAA8ÊÇÒ»¿îÁ÷ÐеÄЭͬ¹ÜÀíÈí¼þ£¬ÔÚ¸÷ÖС¢´óÐÍÆóÒµ»ú¹¹Öй㷺ʹÓá£ÓÉÓÚÖÂÔ¶OA¾É°æ±¾Ä³Ð©½Ó¿ÚÄܱ»Î´ÊÚȨ·ÃÎÊ£¬¶øÇÒ²¿Ãź¯Êý´æÔÚ¹ýÂ˲»×㣬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬿ÉÔÚδÊÚȨµÄÇé¿öÏÂÉÏ´«¶ñÒâ½Å±¾Îļþ£¬´Ó¶ø¿ØÖÆ·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20210119