ÿÖÜÉý¼¶Í¨¸æ-2022-05-10

Ðû²¼Ê±¼ä 2022-05-10

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_GoAhead_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

GoAheadÊÇÒ»¸ö¿ªÔ´(ÉÌÒµÐí¿É)¡¢¼òµ¥¡¢ÇáÇÉ¡¢¹¦Ð§Ç¿´ó¡¢¿ÉÒÔÔÚ¶à¸öƽ̨ÔËÐеÄWebServer £¬¶àÓÃÓÚǶÈëʽϵͳ¡¢ÖÇÄÜÉ豸¡£ÆäÖ§³ÖÔËÐÐASP¡¢JavascriptºÍ³ß¶ÈµÄCGI·¨Ê½ £¬Õâ¸ö©¶´¾Í·ºÆðÔÚÔËÐÐCGI·¨Ê½µÄʱºò¡£GoAheadÔÚ½ÓÊÕµ½ÇëÇóºó £¬½«»á´ÓURL²ÎÊýÖÐÈ¡³ö¼üºÍÖµ×¢²á½øCGI·¨Ê½µÄ»·¾³±äÁ¿ £¬ÇÒÖ»¹ýÂËÁËREMOTE_HOSTºÍHTTP_AUTHORIZATION¡£ÎÒÃÇÄܹ»¿ØÖÆ»·¾³±äÁ¿ £¬¾ÍÓкܶ๥»÷·½Ê½¡£ºÃ±ÈÔÚLinuxÖÐ £¬LD_¿ªÍ·µÄ»·¾³±äÁ¿ºÍ¶¯Ì¬Á´½Ó¿âÓÐ¹Ø £¬ÈçLD_PRELOADÖÐÖ¸¶¨µÄ¶¯Ì¬Á´½Ó¿â £¬½«»á±»×Ô¶¯¼ÓÔØ£»LD_LIBRARY_PATHÖ¸¶¨µÄ·¾¶ £¬·¨Ê½»áÈ¥ÆäÖÐÑ°ÕÒ¶¯Ì¬Á´½Ó¿â¡£ÎÒÃÇ¿ÉÒÔÖ¸¶¨LD_PRELOAD=/proc/self/fd/0 £¬ÒòΪ/proc/self/fd/0Êdz߶ÈÊäÈë £¬¶øÔÚCGI·¨Ê½ÖÐ £¬POSTÊý¾ÝÁ÷¼´Îª³ß¶ÈÊäÈëÁ÷¡£ÎÒÃDZàÒëÒ»¸ö¶¯Ì¬Á´½Ó¿â £¬½«Æä·ÅÔÚPOSTBodyÖÐ £¬·¢Ë͸øhttp://target/cgi-bin/index?LD_PRELOAD=/proc/self/fd/0 £¬CGI¾Í»á¼ÓÔØÎÒÃÇ·¢Ë͵Ķ¯Ì¬Á´½Ó¿â £¬Ôì³ÉÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_FreePBX_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

FreePBXÊÇÒ»¸ö×îÇ¿´óµÄGUI£¨»ùÓÚÍøÒ³µÄ£©ÅäÖÃAsteriskµÄ¹¤¾ß £¬ÔÚÆä13ºÍ14°æ±¾´æÔÚÄþ¾²Â©¶´ £¬Ö÷»úÓб»Ö´ÐÐÈÎÒâϵͳÃüÁîµÄ·çÏÕ¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_WordPress_Levo_Slideshow_2.3_ÈÎÒâÎļþÉÏ´«Â©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

WordPressLevo-Slideshow²å¼þ2.3°æ±¾´æÔÚÎļþÉÏ´«Â©¶´ £¬¸Ã©¶´Ô´ÓÚ¶ÔÉÏ´«Îļþºó׺¼ì²â²»ÑϽ÷ £¬¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ¿ØÖÆÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_CA_Privileged_Access_Manager_ÃüÁî×¢È멶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

CAPrivilegedAccessManager2.8.2¼°¸üÔç°æ±¾ÖдæÔÚÒ»¸öÃüÁî×¢È멶´ £¬¸Ã©¶´ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÖÆÇëÇóÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PixelStor_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2020-6756][CNNVD-202001-346]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

RasilientPixelStor5000K:4.0.1580-20150629£¨KDI°æ±¾£©ÖеÄlanguageOptions.phpÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýlang²ÎÊýÔ¶³ÌÖ´ÐÐÃüÁî¡£

¸üÐÂʱ¼ä£º

20220510

 

½Øͼ20220510161912.png

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PmWiki_PageListSort_Ô¶³Ì´úÂë×¢È멶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

PmWikiÊÇÒ»ÖÖ»ùÓÚWiki¼¼ÊõµÄ¿ªÔ´¶àÈËЭ×÷Õ¾µã´´½¨ºÍά»¤¹¤¾ß¡£PmWiki2.0.0µ½2.2.34°æ±¾ÖдæÔÚÔ¶³ÌPHP´úÂë×¢È멶´¡£¹¥»÷Õß¿ÉÀûÓø鶴ÔÚÊÜÓ°ÏìµÄÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖÐ×¢ÈëºÍÖ´ÐÐÈÎÒâPHP´úÂë £¬Õâ¿ÉÄÜ»á´Ù½ø¹¥»÷Õß²Ù¿ØÓ¦Ó÷¨Ê½ºÍµ×²ãϵͳ £¬»òÕßÔì³ÉÆäËûµÄ¹¥»÷¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Basilic1.5.14-diff.php_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

BasilicÖдæÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£¹¥»÷Õß¿ÉÀûÓø鶴ÔÚÊÜÓ°ÏìÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâÃüÁî¡£Basilic1.5.14°æ±¾ÖдæÔÚ©¶´ £¬ÆäËû°æ±¾Ò²¿ÉÄÜÊܵ½Ó°Ïì¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_WAN-Emulator-v2.3_ÈÎÒâÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

WANEmulatorÊǹãÓòÍøÂçÄ£ÄâÆ÷¡£WANEmulator´æÔÚ·Ç·¨·ÃÎÊ©¶´ £¬dosu¶þ½øÖÆÎļþ°²×°ÁËsetuidrootºó¿É´¥·¢´Ë©¶´ £¬µ¼Öµ±µØ¹¥»÷Õß»ñÈ¡rootȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ºÃÊÓͨÊÓƵ»áÒéϵͳ_ÈÎÒâÎļþÏÂÔØ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ºÃÊÓͨÊÓƵ»áÒéÆóÒµ°æ·þÎñÆ÷¹ÜÀíºǫ́´æÔÚÈÎÒâÎļþÏÂÔØ©¶´ £¬¹¥»÷Õß¿ÉÀûÓø鶴»ñÈ¡Ãô¸ÐÐÅÏ¢¡£Ä¿Ç° £¬¹©Ó¦ÉÌÐû²¼ÁËÄþ¾²Í¨¸æ¼°Ïà¹Ø²¹¶¡ÐÅÏ¢ £¬ÐÞ¸´ÁË´Ë©¶´¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Ruckus_IoT_Controller_Éí·ÝÑéÖ¤Èƹý©¶´[CVE-2020-26879][CNNVD-202010-1425]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

RuckusIoTController£¨<=1.5.1.0.21°æ±¾£©ÖдæÔÚÒ»¸öÉí·ÝÑéÖ¤Èƹý©¶´¡£¸Ã©¶´ÊÇÓÉÓÚ¶Ô¾«ÐÄÉè¼ÆµÄHTTPÇëÇó´¦Öò»Í×Ôì³ÉµÄ £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿±ê·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´ÀûÓø鶴 £¬ÀÖ³ÉÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßÈƹýÉí·ÝÑéÖ¤¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Vtiger-CRM-°²×°½Å±¾_δÊÚȨÖØ×°

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

VtigerCRMÊÇÃÀ¹úVtiger¹«Ë¾µÄÒ»Ì×»ùÓÚSugarCRM¿ª·¢µÄ¿Í»§¹Øϵ¹ÜÀíϵͳ£¨CRM£© £¬ËüÌṩ¹ÜÀí¡¢ÊÕ¼¯¡¢·ÖÎö¿Í»§ÐÅÏ¢µÈ¹¦Ð§¡£InstallModuleÊÇÆäÖеÄÒ»¸ö°²×°Ä £¿é¡£VtigerCRM6.0°æ±¾µÄInstallÄ £¿éÖеÄviews/Index.php½Å±¾ÖдæÔÚÄþ¾²Â©¶´ £¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÏÞÖÆ·ÃÎÊȨÏÞ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍ°üÂÞX-Requested-WithHTTPÍ·ÉèÖõÄÇëÇóÀûÓø鶴ÖØ×°Ó¦Ó÷¨Ê½¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_systeminfo_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÃüÁîµÄ»ØÏÔÐÅÏ¢ £¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ £¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÃüÁîµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220510