ÿÖÜÉý¼¶Í¨¸æ-2022-08-16
Ðû²¼Ê±¼ä 2022-08-16ÐÂÔöʼþ
ʼþÃû³Æ£º | TCP_×¢Èë¹¥»÷_WebLogic_WsrmSequenceContext_XXE×¢Èë[CVE-2019-2650][CNNVD-201904-726] |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHTTP_WebLogic_WsrmSequenceContext_XXE×¢Èë©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£HTTP_WebLogic_WsrmSequenceContext_XXE×¢Èë©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3ÐÒéÖУ¬Í¨¹ý¶ÔT3ÐÒéÖеÄpayload½øÐз´ÐòÁл¯£¬´Ó¶øÊµÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlindXXE¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20220816 |
ʼþÃû³Æ£º | TCP_×¢Èë¹¥»÷_WebLogic_EJBTaglibDescriptor_XXE×¢Èë[CVE-2019-2888][CNNVD-201904-706] |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHTTP_WebLogic_EJBTaglibDescriptor_XXE×¢Èë©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£HTTP_WebLogic_EJBTaglibDescriptor_XXE×¢Èë©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3ÐÒéÖУ¬Í¨¹ý¶ÔT3ÐÒéÖеÄpayload½øÐз´ÐòÁл¯£¬´Ó¶øÊµÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³Ì·´ÐòÁл¯XXE¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20220816 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Joomla_B2jcontact_2.1.17_ÎļþÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | B2J_contactÊÇ×îÊÜ»¶ÓµÄÀ©Õ¹CodextrousÖ®Ò»£¬ÓÃÓÚ´´½¨ÁªÏµ±íµ¥¡£ÕâÖÖ¸ïÃüÐԵĶ๦ЧJoomla_contact×é¼þÊdz¬¼¶Ò×ÓÚ°²×°£¬Í¨¹ýÆä¼ò½àµÄÉè¼ÆºÍÓû§ÓѺõĺó¶ËΪÄú´øÀ´ÖÕ¼«µÄÓû§ÌåÑé¡£ÔÚÆä×é¼þ(2.1.17°æ±¾)ÖдæÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬¹¥»÷Õß»áÀûÓôË©¶´£¬ÉÏ´«¶ñÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20220816 |
ʼþÃû³Æ£º | TCP_Ô¶³Ì¿ØÖÆÈí¼þ_·¢ÏÖToDeskʹÓà |
Äþ¾²ÀàÐÍ£º | Äþ¾²Éó¼Æ |
ʼþÃèÊö£º | ¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚʹÓÃToDesk¡£ToDeskÊÇÒ»¿î¶àƽ̨Զ³Ì¿ØÖÆ/Ô¶³ÌÐÖúÈí¼þ£¬Ö÷´òÁ÷³©ÒÔ¼°¸öÈËÃâ·ÑµÄÌØµã¡£ |
¸üÐÂʱ¼ä£º | 20220816 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ÒÚÈüͨµç×ÓÎĵµ¹ÜÀíϵͳ_dataimport_ÃüÁîÖ´ÐÐ[CNVD-2021-43589] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ÒÚÈüͨµç×ÓÎĵµÄþ¾²¹ÜÀíϵͳ£¨¼ò³ÆCDG£©ÊÇÒ»¿îµç×ÓÎĵµÄþ¾²¼ÓÃÜÈí¼þ£¬¸ÃϵͳÀûÓÃÇý¶¯²ã͸Ã÷¼ÓÃܼ¼Êõ£¬Í¨¹ý¶Ôµç×ÓÎĵµµÄ¼ÓÃܱ£»¤£¬·ÀÖ¹ÄÚ²¿Ô±¹¤Ð¹ÃܺÍÍⲿÈËÔ±·Ç·¨ÇÔÈ¡ÆóÒµºËÐÄÖØÒªÊý¾Ý×ʲú¡£ÒÚÈüͨµç×ÓÎĵµ¹ÜÀíϵͳ´æÔÚÃüÁîÖ´ÐЩ¶´¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´»ñÈ¡ÍøÕ¾·þÎñÆ÷¿ØÖÆÈ¨¡£ |
¸üÐÂʱ¼ä£º | 20220816 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Oracle-Weblogic-console_ȨÏÞÈÆ¹ý[CVE-2020-14883][CNNVD-202010-997] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracleWebLogicconsoleȨÏÞÈÆ¹ý©¶´£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ·ÇÊÚȨ·ÃÎÊweblogicconsole£¬Ö®ºó¿ÉÒÔʹÓÃCVE-2020-14882¿ØÖÆÄ¿±êϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20220816 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache_Druid_δÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | DruidÊǰ¢Àï°Í°ÍÊý¾Ý¿âÊÂÒµ²¿³öÆ·£¬Îª¼à¿Ø¶øÉúµÄÊý¾Ý¿âÁ¬½Ó³Ø£¬DruidÌṩµÄ¼à¿Ø¹¦Ð§£¬¼à¿ØSQLµÄÖ´ÐÐʱ¼ä¡¢¼à¿ØWebURIµÄÇëÇó¡¢Session¼à¿Ø£¬µ±¿ª·¢ÕßÅäÖò»Í×ʱ¾Í¿ÉÄÜÔì³ÉδÊÚȨ·ÃÎÊ©¶´¡£ |
¸üÐÂʱ¼ä£º | 20220816 |
ʼþÃû³Æ£º | TCP_×¢Èë¹¥»÷_WebLogic_ForeignRecoveryContext_XXE×¢Èë[CVE-2019-2648] |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHTTP_WebLogic_ForeignRecoveryContext_XXE×¢Èë©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£HTTP_WebLogic_ForeignRecoveryContext_XXE×¢Èë©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3ÐÒéÖУ¬Í¨¹ý¶ÔT3ÐÒéÖеÄpayload½øÐз´ÐòÁл¯£¬´Ó¶øÊµÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlindXXE¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20220816 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓøÃ©¶´Ö´ÐÐÈÎÒâOGNL±í´ïʽ¡£Â©¶´´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20220816 |