ÿÖÜÉý¼¶Í¨¸æ-2021-12-07
Ðû²¼Ê±¼ä 2021-12-10ÐÂÔöʼþ
ʼþÃû³Æ£º | TCP_Äþ¾²Â©¶´_Apache_ShenYu_Admin_δÊÚȨµÇ¼©¶´_¹¥»÷ʵÑé[CVE-2021-37580][CNNVD-202111-1500] |
Äþ¾²ÀàÐÍ£º | ·ÇÊÚȨ·ÃÎÊ/ȨÏÞÈƹý |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃApache_ShenYu_AdminµÄδÊÚȨµÇ¼©¶´£¬ÈƹýJSONWebToken(JWT)Äþ¾²ÈÏÖ¤£¬Ö±½Ó½øÈëϵͳºǫ́ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | TCP_Äþ¾²Â©¶´_Dubbo_Hessian2ÐÒé·´ÐòÁл¯Â©¶´[CVE-2021-25641] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚͨ¹ý½á¹¹serializationidÀ´½øÐÐδÊÚȨ´úÂëÖ´ÐУ¬Í¨¹ýKryo¡¢FST»òÕßnative-javaµÈÄþ¾²ÐԽϲîµÄÐòÁл¯·½Ê½½øÐз´ÐòÁл¯´úÂëÖ´ÐУ»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³Ì·þÎñµ÷Ó÷½°¸£¬ÒÔ¼°SOA·þÎñÖÎÀí·½°¸¡£ApacheDubboÔÚʵ¼ÊÓ¦Óó¡¾°ÖÐÖ÷ÒªÂôÁ¦½â¾öÂþÑÜʽµÄÏà¹ØÐèÇó¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | TCP_Äþ¾²Â©¶´_Dubbo_Nashorn½Å±¾Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2021-30181] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÔÚ¿ÉÄÜÒѾ¿ØÖÆÈçZooKeeperÅäÖÃÖÐÐĺó£¬Í¨¹ýÅäÖÃÖÐÐÄÀ´½á¹¹¶ñÒâÇëÇó¶ÔDubbo×¢ÈëNashorn½Å±¾£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³Ì·þÎñµ÷Ó÷½°¸£¬ÒÔ¼°SOA·þÎñÖÎÀí·½°¸¡£ApacheDubboÔÚʵ¼ÊÓ¦Óó¡¾°ÖÐÖ÷ÒªÂôÁ¦½â¾öÂþÑÜʽµÄÏà¹ØÐèÇó¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Netgear-ProSAFE-Plus_JGS516PE_δÑéÖ¤Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-26919][CNNVD-202010-350] |
Äþ¾²ÀàÐÍ£º | ·ÇÊÚȨ·ÃÎÊ/ȨÏÞÈƹý |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃCVE-2020-26919©¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁî¡£NetgearProSAFEPlusJGS516PE/GS116Ev2ÊÇÃÀ¹úÍø¼þ(Netgear)¹«Ë¾µÄÒ»¿î½»»»»ú¡£NetgearJGS516PEdevices2.6.0.43֮ǰ°æ±¾´æÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚÉ豸ÔÚ¹¦Ð§¼¶±ðÉÏÊܵ½È±ÉÙ·ÃÎÊ¿ØÖÆ¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_WordPress_XSS½Å±¾×¢È멶´[CVE-2019-16219][CNNVD-201909-549] |
Äþ¾²ÀàÐÍ£º | XSS¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÉ豸ÕýÔÚÀûÓÃNetgea·ÓÉÆ÷Ô¶³ÌÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÉ豸¡£ÔÚNETGEARR7000ÉÏ´æÔÚÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Äþ¾²Â©¶´¡£Â©¶´ÀûÓÃÀֳɺ󣬿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_thinkcmf_ºǫ́´úÂëÖ´ÐЩ¶´[CVE-2019-7580][CNNVD-201902-163] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ipÕýÔÚÀûÓÃthinkcmfµÄºǫ́´úÂëÖ´ÐЩ¶´£¬ÔÚ·ÖÀà¹ÜÀíÒ³Ãæ´´½¨·ÖÀà±ðÃûʱ£¬Ð´Èë¶ñÒâ´úÂë¡£ThinkCMFÊÇÒ»¿îÖ§³ÖSwooleµÄ¿ªÔ´ÄÚÈݹÜÀí¿ò¼Ü(CMF),»ùÓÚThinkPHP¿ª·¢¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_ľÂí_Downloader_APT-C-23_Á¬½Ó_±äÖÖ |
Äþ¾²ÀàÐÍ£º | ÏÂÔØÕßľÂí |
ʼþÃèÊö£º | ¼ì²âµ½APT-C-23ÏÂÔØÆ÷ľÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAPT-C-23ÏÂÔØÆ÷ľÂí¡£APT-C-23ÏÂÔØÆ÷ľÂíÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_DedeCMS_sys_verifies.php_´úÂë×¢È멶´[CVE-2018-9174][CNNVD-201804-087] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈݹÜÀíϵͳ¡£DeDeCMS5.7°æ±¾ÔÚ´æÔÚsys_verifies.php´úÂë×¢È멶´£¬¸Ã©¶´Ô´ÓÚ¶Ô´«Èë²ÎÊýrefiles¹ýÂ˲»ÑϽ÷£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓôË©¶´Ö´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Phpcms_insdex.php_ǰ̨Getshell |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚÀûÓÃPhpcmsǰ̨ע²áÓû§µÄ½çÃ棬½øÐÐgetshell²Ù×÷£¬µ«Ä¿Ç°¹æÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñgetshell£»£»PHPCMSÊÇÒ»¿îÍøÕ¾¹ÜÀíÈí¼þ¡£¸ÃÈí¼þ½ÓÄÉÄ£¿é»¯¿ª·¢£¬Ö§³Ö¶àÖÖ·ÖÀ෽ʽ£¬Ê¹ÓÃËü¿É·½±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Phpcms_insdex.php_ºǫ́Getshell |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚÀûÓÃPhpcmsºǫ́ҳÃ棬½øÐÐgetshell²Ù×÷£¨Ä¿Ç°¸Ã¹æÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñÒѾgetshell£©£»PHPCMSÊÇÒ»¿îÍøÕ¾¹ÜÀíÈí¼þ¡£¸ÃÈí¼þ½ÓÄÉÄ£¿é»¯¿ª·¢£¬Ö§³Ö¶àÖÖ·ÖÀ෽ʽ£¬Ê¹ÓÃËü¿É·½±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_DedeCMS_stepselect_main.php_´úÂë×¢È멶´[CVE-2018-9175][CNNVD-201804-086] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈݹÜÀíϵͳ¡£DeDeCMS5.7°æ±¾ÔÚ´æÔÚstepselect_main.php´úÂë×¢È멶´£¬¸Ã©¶´Ô´ÓÚ¶Ô´«Èë²ÎÊýegroup¹ýÂ˲»ÑϽ÷£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓôË©¶´Ö´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_DedeCMS_ºǫ́ÈÎÒâ´úÂëÖ´ÐЩ¶´[CVE-2018-7700][CNNVD-201803-954] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | DedeCMS£¨Ö¯ÃÎÄÚÈݹÜÀíϵͳ£©ÊÇÖйú׿׿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼¡¢¹ÜÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈݹÜÀíϵͳ£¨CMS£©¡£DesdevDedeCMS5.7°æ±¾ÖдæÔÚÈÎÒâ´úÂëÖ´ÐЩ¶´¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòtag_test_action.phpÎļþ·¢ËÍ¡®partcode¡¯²ÎÊýÀûÓø鶴ִÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_VMware_Spring_Cloud_Netflix_´úÂëÖ´ÐЩ¶´[CVE-2021-22053][CNNVD-202111-1645] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | SpringCloudNetflixÊÇÒ»Ì×ÂþÑÜʽ·þÎñ¿ò¼ÜµÄ·â×°£¬°üÂÞ·þÎñµÄ·¢ÏÖºÍ×¢²á£¬¸ºÔؾùºâ¡¢¶Ï·Æ÷¡¢REST¿Í»§¶Ë¡¢ÇëÇó·Óɵȡ£¸Ã©¶´ÊÇÓÉÓÚVMwareSpringCloudÔÚͬʱʹÓÃspring-cloud-netflix-hystrix-dashboardºÍspring-boot-starter-thymeleafµÄÓ¦Ó÷¨Ê½Ê±£¬¹ûÈ»ÁËÔÚ½âÎöÊÓͼģ°åÆÚ¼äÖ´ÐÐÇëÇóURI·¾¶ÖÐÌá½»´úÂëµÄÒªÁì¡£µ±ÔÚ¡®/hystrix/monitor;[user-provideddata]`ÉÏ·¢³öÇëÇóʱ£¬`hystrix/monitor`ºóÃæµÄ·¾¶ÔªËؽ«±»Ê¶±ðΪSpringEL±í´ïʽ£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_DedeCMS_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | DedeCMS£¨Ö¯ÃÎÄÚÈݹÜÀíϵͳ£©ÊÇÖйú׿׿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼¡¢¹ÜÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈݹÜÀíϵͳ£¨CMS£©¡£DedecmsV5.7SP2°æ±¾ÖеÄtpl.phpÖдæÔÚ´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸Ã©¶´ÔÚÔö¼ÓбêÇ©ÖÐÉÏ´«Ä¾Âí£¬»ñÈ¡webshell¡£¸Ã©¶´ÀûÓÃÐèÒªµÇ¼ºǫ́£¬¶øÇÒºǫ́µÄÕË»§È¨ÏÞÊǹÜÀíԱȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | ÷ÈħӰϷ·¨Ê½(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉƵÄÇ¿´óÊÓƵӰϷϵͳ¡£ÍêÃÀÖ§³ÖÖÚ¶àÊÓƵÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¸Ã©¶´·¢ÉúÔÒòΪ¹ýÂ˲»ÑϽ÷µ¼Ö¹¥»÷Õß¿ÉÒÔÖ±½ÓÔÚÄÚÖÃÄ£°åÖÐ×¢Èë¶ñÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_ÅÀ³æBot·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | ÍøÒ³ÅÀ³æ |
ʼþÃèÊö£º | ¼ì²âµ½ÅÀ³æBot¶ÔÄ¿µÄIPÖ÷»úµÄweb·ÃÎÊ,¿ÉÄÜÔÚ¶ÔÄ¿µÄIPÖ÷»ú½øÐÐÒ³ÃæÅÀÈ¡¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_TP-LINK_TL-WR840N_EU(V5)_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2021-41653][CNNVD-202111-1211] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | TP-LINKTL-WR840NÊÇÒ»¿îÎÞÏß·ÓÉÆ÷£¬ÐŵÀÊýΪ13£¬Ö§³ÖVPN¹¦Ð§¡£TP-LINKTL-WR840NEU(V5)RouterµÄPING¹¦Ð§´æÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£¹¥»÷Õß¿ÉÀûÓø鶴ͨ¹ýIPµØÖ·ÖÐÌØÖƵÄÓÐЧÔغÉÖ´ÐÐÔ¶³ÌÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_º£¿µÍþÊÓIPÉãÏñ»ú/NVR_ÃüÁî×¢È멶´[CVE-2021-36260][CNNVD-202109-1602] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | º£¿µÍþÊÓIPÉãÏñ»ú/NVRÉ豸¹Ì¼þÖдæÔÚÒ»¸öδÈÏÖ¤ÃüÁî×¢È멶´£¬ÓÉÓÚ¶ÔÊäÈë²ÎÊýУÑé²»³äʵ£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍ´øÓжñÒâÃüÁîµÄ±¨Îĵ½ÊÜÓ°ÏìÉ豸£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÒÔµ¼ÖÂÃüÁîÖ´ÐС£º£¿µÍþÊÓÒÑÐû²¼°æ±¾ÐÞ¸´¸Ã©¶´£¬¸Ã©¶´»áÓ°ÏìIPÉãÏñÍ·ºÍNVRÉ豸¹Ì¼þ£¬ÆäÖаüÂÞ2021Äê6ÔµÄ×îй̼þÒÔ¼°2006ÄêÐû²¼µÄ¹Ì¼þ¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²É¨Ãè_WEBɨÃèÆ÷ÐÐΪ |
Äþ¾²ÀàÐÍ£º | ÍøÂçɨÃè |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPµØÖ·µÄÖ÷»úÕýÔÚʹÓÃWEBɨÃ蹤¾ß(È磺sqlmap¡¢nessusµÈ)¶ÔÄ¿µÄIPµØÖ·½øÐЩ¶´É¨Ãè¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×ö·þÎñɨÃ衢©¶´²âÊԵȡ£Í¨¹ý©¶´É¨Ã裬¿ÉÒÔ×Ô¶¯¿ìËÙ̽²âһЩ³£¼û©¶´Çé¿ö£¬µ±´æÔÚ©¶´Ê±±ãÓÚºóÐø½øÐÐÀûÓù¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20211207 |