ÿÖÜÉý¼¶Í¨¸æ-2021-10-26

Ðû²¼Ê±¼ä 2021-10-27

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_QNAP-QTS_ÃüÁî×¢Èë[CVE-2017-7876][CNNVD-201704-779]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

QNAPSystemsQNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸´¢´æ¡¢¹ÜÀí¡¢±¸·Ý£¬¶àýÌåÓ¦Óü°Äþ¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.6build20170517֮ǰµÄ°æ±¾ÖдæÔÚÃüÁî×¢È멶´¡£¹¥»÷Õß¿ÉÀûÓø鶴עÈëÃüÁî¡£

¸üÐÂʱ¼ä£º

20211026

 


ʼþÃû³Æ£º

TCP_Äþ¾²Â©¶´_VMware_vCenter_Server_·þÎñÆ÷¶ËÇëÇóαÔ쩶´[CVE-2021-21973][CNNVD-202102-1559]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃVMwarevCenterServer·þÎñÆ÷¶ËÇëÇóαÔ쩶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¸Ã©¶´Ô´ÓÚVMwarevCenterServer²å¼þÖжÔÓû§ÌṩµÄÊäÈëÑéÖ¤²»Í×£¬Î´¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖƵÄHTTPÇëÇó£¬ÆÛÆ­Ó¦Ó÷¨Ê½ÏòÈÎÒâϵͳÌᳫÇëÇóʵÏÖÄÚÍøɨÃ裬»ñÈ¡ÄÚÍøÐÅÏ¢£¬µ¼ÖÂÐÅϢй¶¡£

¸üÐÂʱ¼ä£º

20211026

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Jetty_WEB-INF_ÐÅϢ鶩¶´[CVE-2021-34429]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

EclipseJetty°æ±¾9.4.37-9.4.42¡¢10.0.1-10.0.5ºÍ11.0.1-11.0.5£¬¿ÉÒÔʹÓÃһЩ±àÂë×Ö·û½á¹¹ÌØÊâµÄURIÀ´·ÃÎÊWEB-INFĿ¼µÄÄÚÈÝ¡£

¸üÐÂʱ¼ä£º

20211019

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_D-LinkDSL-2640U&DSL-2540U_ÃüÁîÖ´ÐÐ[CVE-2018-5371][CNNVD-201801-545]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

D-LinkDSL-2640UÉ豸£¨¹Ì¼þΪIM_1.00ºÍME_1.00£©ºÍDSL-2540UÉ豸£¨¹Ì¼þΪME_1.00£©ÉϵÄdiag_ping.cmdÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýHTTPGETÇëÇóµÄipaddr×Ö¶ÎÖеÄshellÔª×Ö·ûÖ´ÐÐÈÎÒâOSÃüÁî¡£

¸üÐÂʱ¼ä£º

20211026

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Subrion-CMS_´úÂëÖ´ÐÐ[CVE-2018-19422][CNNVD-201811-628]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

SubrionCMSÊÇSubrionÍŶӿª·¢µÄÒ»Ì×»ùÓÚPHPµÄÄÚÈݹÜÀíϵͳ£¨CMS£©¡£¸Ãϵͳ¿É±»¼¯³Éµ½ÍøÕ¾£¬²¢Ö§³Ö¶àÖÖÀ©Õ¹²å¼þµÈ¡£SubrionCMS4.2.1°æ±¾ÖеÄ/panel/uploads´æÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ.htaccessÎļþûÓнûÖ¹¶ÔphtºÍpharÎļþµÄÖ´ÐвÙ×÷¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú.pht»ò.pharÎļþÀûÓø鶴ִÐÐÈÎÒâµÄPHP´úÂë¡£

¸üÐÂʱ¼ä£º

20211026

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_OpenMRS_´úÂëÖ´ÐÐ[CVE-2018-19276][CNNVD-201902-602]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

OpenMRSÊÇÃÀ¹úOpenMRS¹«Ë¾µÄÒ»Ì׿ªÔ´µÄµç×Ó²¡Àúϵͳ¡£OpenMRSPlatform2.24.0֮ǰ°æ±¾ÖдæÔÚÄþ¾²Â©¶´¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Billion_5200W-T_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2017-18372][CNNVD-201905-077]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Billion5200W-T·ÓÉÆ÷ÔÚʱ¼äÉèÖù¦Ð§ÖдæÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£¸Ã©¶´Î»ÓÚtools_time.aspÒ³Ã棬Զ³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÃüÁî²¢Ö´ÐС£

¸üÐÂʱ¼ä£º

20211026

 

 

ʼþÃû³Æ£º

UDP_DD-WRT_»º³åÇøÒç³ö©¶´[CVE-2021-27137]

Äþ¾²ÀàÐÍ£º

»º³åÒç³ö

ʼþÃèÊö£º

DD-WRTÊÇÒ»¸ö»ùÓÚLinuxµÄÎÞÏß·ÓÉÈí¼þ¡£¸Ã©¶´£¬Í¨¹ý»º³åÇøÒç³ö¿ÉÖ´ÐÐÈÎÒâÃüÁµ¼ÖÂÖ÷»úÓб»½Ó¹ÜµÄ·çÏÕ¡£

¸üÐÂʱ¼ä£º

20211026

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Billion_5200W-T_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2017-18369][CNNVD-201905-073]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Billion5200W-T·ÓÉÆ÷ÔÚÔÚadv_remotelog.aspÎļþÖдæÔÚδ¾­Éí·ÝÑéÖ¤µÄÃüÁî×¢Èë¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÃüÁî²¢Ö´ÐС£

¸üÐÂʱ¼ä£º

20211026

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_OTRS_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2017-16921][CNNVD-201711-917]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÔÚOTRS6.0.xÖÁ6.0.1¡¢OTRS5.0.xÖÁ5.0.24ºÍOTRS4.0.xÖÁ4.0.26ÖУ¬ÒÔÊðÀíÉí·ÝµÇ¼OTRSµÄ¹¥»÷Õß¿ÉÒÔÀûÓÃ±íµ¥²ÎÊý£¨ÓëPGPÏà¹Ø£©²¢ÔÚOTRS»òWeb·þÎñÆ÷Óû§µÄȨÏÞÏÂÖ´ÐÐÈÎÒâshellÃüÁî¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_HPEÖÇÄܹÜÀíÖÐÐÄ_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-7184][CNNVD-202010-863]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

HPEIntelligentManagementCenterÊÇÃÀ¹ú»ÝÆÕÆóÒµ¹«Ë¾£¨HewlettPackardEnterprise£¬HPE£©µÄÒ»Ì×ÍøÂçÖÇÄܹÜÀíÖÐÐĽâ¾ö·½°¸¡£¸Ã½â¾ö·½°¸¿ÉÌṩÕû¸öÍøÂ緶ΧµÄ¿ÉÊÓÐÔ£¬ÊµÏÖ¶Ô×ÊÔ´¡¢·þÎñºÍÓû§µÄÈ«Ãæ¹ÜÀí¡£HPEIntelligentManagementCenter(iMC)7.3֮ǰ°æ±¾´æÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚviewbatchtaskresultdetailfact±í´ïʽÓïÑÔ×¢ÈëÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_FreePBXÄþ¾²Èƹý©¶´[CVE-2019-19006][CNNVD-201911-1264]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÀûÓÃFreePBXÄþ¾²Èƹý©¶´¹¥»÷Ä¿µÄIPÉ豸¡£FreePBX£¨Ç°³ÆAsteriskManagementPortal£©ÊÇFreePBXÏîÄ¿µÄÒ»Ì×ͨ¹ýGUI£¨»ùÓÚÍøÒ³µÄͼÐλ¯½Ó¿Ú£©ÅäÖÃAsterisk£¨IPµç»°ÏµÍ³£©µÄ¹¤¾ß¡£FreePBX115.0.16.26¼°Ö®Ç°°æ±¾¡¢14.0.13.11¼°Ö®Ç°°æ±¾ºÍ13.0.197.13¼°Ö®Ç°°æ±¾ÖдæÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓнøÐÐÕýÈ·µÄ·ÃÎÊ¿ØÖÆ¡£¹¥»÷Õß¿ÉÀûÓø鶴ÈƹýÃÜÂëÉí·ÝÑéÖ¤²¢·ÃÎÊ·þÎñ¹¦Ð§¡£

¸üÐÂʱ¼ä£º

20211026

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_D-Link_DIR-859Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-17621][CNNVD-201912-1224]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÀûÓÃD-Link_DIR-859Ô¶³ÌÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÉ豸¡£D-LinkDIR-859É豸LAN²ãÖзºÆðδ¾­Éí·ÝÑéÖ¤µÄÃüÁîÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20211026

 


ʼþÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_VMware_NSX_SD-WAN_Edge_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2018-6961][CNNVD-201805-1140]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃVMware_NSX_SD-WANEdgeµÄ©¶´½øÐй¥»÷ £»VMwareSD-WANEdgeÊÇÒ»¿îÁã½Ó´¥Ê½ÆóÒµ¼¶É豸,Äܹ»ÒÔ¾­¹ýÓÅ»¯µÄ·½Ê½Îª×¨ÓС¢¹«¹²»ò»ìºÏÓ¦ÓÃ,ÒÔ¼°¼ÆËãºÍÐéÄ⻯·þÎñÌṩÄþ¾²Á¬½Ó¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ZyXEL-CloudCNM-SecuManager_´úÂë×¢Èë[CVE-2020-15348][CNNVD-202006-1754]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ZyxelCNMSecuManager3.1.0ºÍ3.1.1°æ´æÔÚÓ²±àÂë»úÃÜ¡¢Éí·ÝÑéÖ¤¶ªÊ§¡¢ºóÃźÍÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£Í¨¹ýdelete_cpes_by_ids½øÐдúÂë×¢Èë¿ÉÖ´ÐÐÈÎÒâ´úÂ룬Σº¦Ö÷»úÄþ¾²¡£

¸üÐÂʱ¼ä£º

20211026

 

ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_FCKeditor_ASP_½âÎö©¶´ÉÏ´«½Å±¾Ö´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃFCKeditor_ASP_½âÎö©¶´ÉÏ´«½Å±¾Ö´ÐЩ¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£FCKeditorÊÇ¿ªÔ´µÄÍøÒ³±à¼­Æ÷£¬±»ÖÚ¶à´øÓб༭¹¦Ð§µÄÍøÕ¾»òÕßCMSʹÓá£FCKeditor´æÔÚFCKeditor_ASP_½âÎö©¶´ÉÏ´«½Å±¾Ö´ÐЩ¶´£¬¹¥»÷ÕßÀûÓôË©¶´ÉÏ´«ÈÎÒâÀàÐÍÎļþ£¬»ñÈ¡Ä¿±êÍøÕ¾µÄwebshell£¬½øÒ»²½»ñÈ¡ÍøÕ¾¿ØÖÆȨ¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20211026


 

ʼþÃû³Æ£º

HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´¶ÔÄ¿µÄIPÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£FastJsonÊÇ°¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬Ëü¿ÉÒÔ½âÎöJSON¸ñʽµÄ×Ö·û´®£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌص㣬ӦÓ÷¶Î§ºÜ¹ã¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211026


ɾ³ýʼþ


1¡¢HTTP_ͨÓÃ_unicodeÈƹý

2¡¢SMB_¾Ü¾ø·þÎñ_Winnuke_¹¥»÷[CVE-1999-0153]