ÿÖÜÉý¼¶Í¨¸æ-2022-08-09
Ðû²¼Ê±¼ä 2022-08-09
ʼþÃû³Æ£º | HTTP_Microsoft-Exchange-SERVER_·þÎñÆ÷¶ËÇëÇóαÔì[CVE-2021-26855] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | µ±Ç°Ö÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_·þÎñÆ÷¶ËÇëÇóαÔì¹¥»÷ |
¸üÐÂʱ¼ä£º | 20220809 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | TCP_ľÂíºóÃÅ_vbs_webshell_Ò»¾ä»°Ä¾Âí |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«VBSÒ»¾ä»°Ä¾ÂíµÄÐÐΪ¹¥»÷ÕßʵÑéÏò·þÎñÆ÷ÉÏ´«VBSÒ»¾ä»°Ä¾ÂíÎļþ£¬Èç¹ûÉÏ´«Àֳɽ«Í¨¹ýÒ»¾ä»°Ä¾ÂíÁ¬½Ó¹¤¾ß¶Ô·þÎñÆ÷½øÐпØÖÆ¡£ÊµÑéÉÏ´«Webshell£¬»ñÈ¡ÍøÕ¾¿ØÖÆȨ¡£ |
¸üÐÂʱ¼ä£º | 20220809 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache-Spark-doAS_ÃüÁî×¢Èë[CVE-2022-33891] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheSparkUIͨ¹ýÅäÖÃÑ¡Ïîspark.acls.enableÉí·ÝÑéÖ¤¹ýÂËÆ÷£¬¼ì²éÓû§ÊÇ·ñ¾ßÓмì²ì»òÐÞ¸ÄÓ¦Óá£Èç¹ûÆôÓÃÁËACL£¬ÔòHttpSecurityFilterÖеĴúÂëÔÊÐíijÈËͨ¹ýÌṩÈÎÒâÓû§ÃûÀ´Ö´ÐÐÄ£Äâ¡£¶ñÒâÓû§¿ÉÄÜÈƹýȨÏÞ¼ì²é¹¦Ð§£¬ÊäÈë¹¹½¨Ò»¸öUnixshellÃüÁ¶øÇÒÖ´ÐÐËü¡£½«µ¼ÖÂÖ´ÐÐÈÎÒâshellÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20220809 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Master-IP-CAM-01_ÃüÁîÖ´ÐÐ[CVE-2019-8387] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | MasterIPCAM01ÊÇÒ»¿îÍøÂçÉãÏñ»ú¡£MasterIPCAM013.3.4.2103°æ±¾ÖдæÔÚÃüÁî×¢È멶´¡£¸Ã©¶´Ô´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÃüÁî¹ý³ÌÖУ¬ÍøÂçϵͳ»ò²úÎïδÕýÈ·¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¹¥»÷Õß¿ÉÀûÓø鶴ִÐзǷ¨ÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20220809 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.3.2ÒÔÏÂ_ȨÏÞÈƹý[CVE-2016-6802][CNNVD-201609-372] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£Ä¿Ç°³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖнøÐÐÉí·ÝÑéÖ¤£¬ÊÚȨµÈ¡£¶ÔÓÚApacheShiro1.3.2֮ǰµÄ°æ±¾£¬Ê¹ÓÃÒÔ/xx/../¿ªÍ·µÄurl¿ÉÒÔÈƹýshiroµÄÉí·ÝÑéÖ¤ |
¸üÐÂʱ¼ä£º | 20220809 |
ʼþÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø鶴ִÐÐÈÎÒâOGNL±í´ïʽ¡£Â©¶´´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20220809 |