ÿÖÜÉý¼¶Í¨¸æ-2021-11-23
Ðû²¼Ê±¼ä 2021-12-10ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_F5_BIG_IP_TMM_»º³åÇøÒç³ö©¶´[CVE-2021-22991][CNNVD-202103-784] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | F5BIG-IPÊÇÃÀ¹úF5¹«Ë¾µÄÒ»¿î¼¯³ÉÁËÍøÂçÁ÷Á¿¹ÜÀí¡¢Ó¦Ó÷¨Ê½Äþ¾²¹ÜÀí¡¢¸ºÔؾùºâ¡¢DDoS·ÀÓùµÈ¹¦Ð§µÄÓ¦Óý»¸¶Æ½Ì¨¡£F5BIG-IP´æÔÚÄþ¾²Â©¶´£¬Á÷Á¿¹ÜÀí΢ÄÚºË(TrafficManagementMicrokernel,TMM)URIµÄ¹æ·¶»¯¿ÉÄÜ»á´íÎóµØ´¦ÖöÔÐéÄâ·þÎñÆ÷µÄÇëÇ󣬴Ӷø´¥·¢»º³åÇøÒç³ö£¬µ¼Ö¾ܾø·þÎñ¹¥»÷¡£ÔÚÒ»¶¨Ìõ¼þÏ£¬¿ÉÄÜÈƹý»ùÓÚURLµÄ·ÃÎÊ¿ØÖÆ£¬Ôì³ÉÔ¶³ÌÃüÁîÖ´ÐС£¸Ã©¶´Í¨¹ý¹¹½¨ÀàËÆHTTPµÄÇëÇó´¥·¢ÃüÁîÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_ͨÓÃ_XSSƽ̨¶ñÒâ´úÂëÖ²Èë |
Äþ¾²ÀàÐÍ£º | ÆäËû×¢Èë |
ʼþÃèÊö£º | ¼ì²âµ½Ä¿µÄIPÖ÷»úÒ³Ãæ±»Ö²ÈëXSSƽ̨µÄ¶ñÒâhtml´úÂë¡£XSSÓÖ½ÐCSS(CrossSiteScript)£¬¿çÕ¾½Å±¾¹¥»÷¡£ËüÖ¸µÄÊǶñÒâ¹¥»÷ÕßÍùWebÒ³ÃæÀï²åÈë¶ñÒâhtml´úÂ룬µ±Óû§ä¯ÀÀ¸Ãҳ֮ʱ£¬Ç¶ÈëÆäÖÐWebÀïÃæµÄhtml´úÂë»á±»Ö´ÐУ¬´Ó¶øµ½´ï¶ñÒâÓû§µÄÌØÊâÄ¿µÄ£¬Èç»ñÈ¡Ãô¸ÐÐÅÏ¢¡£XSSƽ̨ÔòÊÇÓÃÀ´·ºÖ¸½ÓÊÕ¶ñÒâXSS¹¥»÷»ñÈ¡µÄÃô¸ÐÐÅÏ¢µÄÒ»ÖÖƽ̨£¬Ò»°ã¾ßÓÐÄ£¿é»¯µÄXSSpayload£¬Í¨¹ý½«ÆäÖ²ÈëÓû§ä¯ÀÀÆ÷£¬¿ØÖÆÊܺ¦Õßä¯ÀÀÆ÷Ïòƽ̨·¢ËÍÃô¸ÐÐÅÏ¢²¢¼Ç¼¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Apache_Solr<=8.8.2_ÈÎÒâÎļþɾ³ý©¶´ |
Äþ¾²ÀàÐÍ£º | ÆäËû¹¥»÷ÀûÓà |
ʼþÃèÊö£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚÀûÓÃApacheSolr<=8.8.2ÈÎÒâÎļþɾ³ý©¶´¡£¹¥»÷Õß¿ÉÀûÓôË©¶´½á¹¹¶ñÒâµÄrequesthandler£¬·ÃÎÊÌض¨urlºó¿É´¥·¢É¾³ýÊܺ¦IPÖ÷»úÉϵÄÈÎÒâÖ¸¶¨Îļþ¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_VoIPmonitor_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2021-30461][CNNVD-202105-1992] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | VoIPmonitorÊÇ¡°¾ßÓÐÔÚLinuxÉÏÔËÐеÄSIPRTPºÍRTCPVoIPÐÒéµÄ¾ßÓÐÉÌҵǽ˵ĿªÔ´ÍøÂçÊý¾Ý°üÐá̽Æ÷¡±¡£VoIPmonitorWeb½çÃ棬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³ÌÓû§´¥·¢VoIPmonitorÖеÄÔ¶³ÌPHP´úÂëÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Workreap_ÎļþÉÏ´«Â©¶´[CVE-2021-24499] |
Äþ¾²ÀàÐÍ£º | ÎļþÉÏ´« |
ʼþÃèÊö£º | AmentotechWorkreap<2.2.2°æ±¾´æÔÚÒ»¸öδ¾Éí·ÝÑéÖ¤ÈÎÒâÎļþÉÏ´«Â©¶´£¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¸Ã©¶´Ô´ÓÚ`workreap_award_temp_file_uploader`ºÍ`workreap_temp_file_uploader`ûÓÐÖ´ÐÐnonce¼ì²é£¬»òÒÔÈκÎÆäËû·½Ê½ÑéÖ¤ÇëÇóÊÇ·ñÀ´×ÔÓÐЧÓû§£¬ÔÊÐí½«ÈÎÒâÎļþÉÏ´«µ½uploads/workreap-tempĿ¼¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ÏÂÔØÕßľÂí |
ʼþÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬ÔËÐк󣬿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾£¬ÈçºóÃŵȡ£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_·ºÎ¢OA_eoffice8_ÈÎÒâÎļþÉÏ´«Â©¶´ |
Äþ¾²ÀàÐÍ£º | ÎļþÉÏ´« |
ʼþÃèÊö£º | ·ºÎ¢OA-eoffice8ϵͳ´æÔÚǰ̨ÈÎÒâÎļþÉÏ´«Â©¶´£¬Í¨¹ý´Ë©¶´¹¥»÷Õß¿ÉÉÏ´«ÈÎÒâphp¸ñʽÎļþ£¬ºó¶Ë·þÎñÆ÷»áÀֳɽâÎö¸ÃÎļþ£¬µ¼Ö¿Éͨ¹ý´Ë©¶´Ö±½Ó»ñȡϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_SonarQube_δÊÚȨ·ÃÎÊ©¶´[CVE-2020-27986][CNNVD-202010-1588] |
Äþ¾²ÀàÐÍ£º | Ãô¸ÐÐÅϢй¶ |
ʼþÃèÊö£º | SonarQubeÊÇÈðÊ¿SonarSource¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ´úÂëÖÊÁ¿¹ÜÀíϵͳ¡£SonarQube8.4.2.36762°æ±¾´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýapi/settings/values·¢ÏÖÃ÷ÎÄSMTP¡¢SVNºÍGitLabƾ¾Ý¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_"font-family:ËÎÌå">¿ÉÒÉwebshell |
Äþ¾²ÀàÐÍ£º | ÎļþÉÏ´« |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÕýÔÚÉÏ´«¿ÉÒÉ"font-family:ËÎÌå">µÄwebshellÎļþ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_ľÂí_Win32.Echelon_Stealer_Á¬½ÓC2·þÎñÆ÷_ÉÏ´«ÇÔÃÜÐÅÏ¢ |
Äþ¾²ÀàÐÍ£º | ÇÔÃÜľÂí |
ʼþÃèÊö£º | Echelon_StealerÊÇÒ»¸öÇÔÃÜľÂí£¬Ê¹ÓÃC#ÓïÑÔ±àд¶ø³É¡£EchelonStealerµÄ×÷ÕßÊÇÒ»¸öÃûΪ¡°Madcode¡±µÄÍøÂçÆ×Ó¡£EchelonStealerÔÚGitHubƽ̨ÉϹûÈ»Ðû²¼¡£EchelonStealerµÄÖ÷ҪĿ±êÊÇ´ÓÆäÄ¿±ê»ñÈ¡Ãô¸ÐÐÅÏ¢£¬ÒԵǼƾ¾Ý¡¢¸öÈ˶Ի°¡¢¼ÓÃÜ»õ±ÒÇ®°üÐÅÏ¢¡¢Ãô¸ÐÎļþµÈΪĿ±ê¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÇëÇó3 |
Äþ¾²ÀàÐÍ£º | ÍÚ¿óÈí¼þ |
ʼþÃèÊö£º | ¼ì²âµ½ÍÚ¿óľÂíÊÔͼÁ¬½ÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂíʵÑéÁ¬½Ó¿ó³Ø£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬ÏûºÄCPU×ÊÔ´¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_ThinkPHP5.0.x-5.0.23Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP¿ò¼ÜÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬ÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£ThinkPHPÊÇÒ»¸öÁ÷ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£µ±WebÍøÕ¾ÊÇ»ùÓÚThinkPHP¿ò¼Ü¿ª·¢Ê±£¬¿ÉÄÜ´æÔڸ鶴ʱ¡£¹¥»÷Õß·¢Ë;«ÐĽṹµÄPHP´úÂëÔÚÄ¿±êÖ÷»úÉÏÖ´ÐУ¬Æóͼ½øÒ»²½¿ØÖÆ·þÎñÆ÷¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_ͨÓÃʼþ_·¢ÏÖʹÓÃunicode±àÂë |
Äþ¾²ÀàÐÍ£º | ÆäËû¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | JavaĬÈϵıàÂ뷽ʽΪUnicode£¬ÔÚjavaÓïÑԺͲ¿ÃÅ.net·¨Ê½ÖУ¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_D-Link-HNAP-SoapAction-HeaderÃüÁîÖ´ÐЩ¶´[CVE-2015-2051] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | D-LinkDIR-645Wired/WirelessRouterÊÇÓÑѶ(D-Link)¹«Ë¾µÄÒ»¿îÖÇÄÜÎÞÏß·ÓÉÆ÷²úÎʹÓÃ1.04b12¼°Ö®Ç°°æ±¾¹Ì¼þµÄD-LinkDIR-645ÖдæÔÚÄþ¾²Â©¶´£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý¶ÔHNAP½Ó¿ÚÖ´ÐÐGetDeviceSettings²Ù×÷£¬ÀûÓø鶴ִÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Thinkphp3.2.x_Îļþ°üÂÞ©¶´ |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | PHPUnitÊÇPHP³ÌʽÓïÑÔÖÐ×î³£¼ûµÄµ¥Ôª²âÊÔ(unittesting)¿ò¼Ü£¬Í¨³£phpunitʹÓÃcomposer·Ç³£Á÷ÐеÄPHPÒÀÀµ¹ÜÀíÆ÷½øÐв¿Êð,½«»áÔÚµ±Ç°Ä¿Â¼´´½¨Ò»¸övendorÎļþ¼Ð.phpunitÉú²ú»·¾³ÖÐÈÔÈ»°²×°ÁËËü,Èç¹û¸Ã±àдÆ÷Ä£¿é´æÔÚÓÚWeb¿É·ÃÎÊĿ¼£¬Ôò´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÇëÇó2 |
Äþ¾²ÀàÐÍ£º | ÍÚ¿óÈí¼þ |
ʼþÃèÊö£º | ¼ì²âµ½ÍÚ¿óľÂíÊÔͼÁ¬½ÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂíʵÑéÁ¬½Ó¿ó³Ø£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬ÏûºÄCPU×ÊÔ´¡£ |
¸üÐÂʱ¼ä£º | 20211123 |
ʼþÃû³Æ£º | HTTP_Jenkins-Groovy-Sandbox-breakout_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½HTTP_Jenkins-Groovy-Sandbox-breakout_Ô¶³Ì´úÂëÖ´Ðй¥»÷¡£groovyɳÏ䣬±àÒëʱ¼äת»»Æ÷ÔÚÏÞÖÆÐÔɳÏäÖÐÔËÐÐGroovy´úÂë¡£Äþ¾²Ö´Ðв»ÊÜÐÅÈεĽű¾¡£´Ë©¶´ÈƹýÁËJenkinsµÄGroovyɳÏ䣬µ¼ÖÂÁË´úÂëÖ´ÐС£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211123 |