ÿÖÜÉý¼¶Í¨¸æ-2022-09-20
Ðû²¼Ê±¼ä 2022-09-20ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Pi-hole_v4.4_ÎļþÉÏ´«[CVE-2020-11108][CNNVD-202005-403] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Pi-holeÊÇÒ»¸öÓÃÓÚÄÚÈݹýÂ˵ÄDNS·þÎñÆ÷£¬v4.4¼°Æä֮ǰµÄ°æ±¾´æÔÚÎļþÉÏ´«Â©¶´£¬ÔÚ¹¥»÷ÕߵǼºó¿ÉÒÔÉÏ´«¶ñÒâwebshell»ñȡϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Online-Voting-System_1.0_ÎļþÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | OnlineVotingSystemÊÇרÃÅΪCHMSCµÄÖÐѧ/¸ßÖпª·¢µÄϵͳ£¬Æä1.0¼°Æä֮ǰµÄ°æ±¾´æÔÚÎļþÉÏ´«Â©¶´£¬ÔÚ¹¥»÷ÕߵǼºó¿ÉÒÔÉÏ´«¶ñÒâwebshell»ñȡϵͳȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Spring_actuator_heapdump_·ÇÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Spring¿ò¼ÜÖеÄactuator×é¼þ´æÔÚδÊÚȨ·ÃÎÊ©¶´£¬¹¥»÷Õß¿Éͨ¹ý·ÃÎÊurl+/actuator/heapdump»ñÈ¡·þÎñÆ÷Ãô¸ÐÄÚ´æÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Ewebeditor_aStyle·ç¸ñ½ç˵_ÎļþÉÏ´« |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | PHP°æ±¾µÄewebeditor²¢Ã»ÓÐʹÓÃÊý¾Ý¿âÀ´Éú´æÅäÖÃÐÅÏ¢£¬ËùÓÐÐÅϢλÓÚphp/config.phpÖУ¬Ëü½«ËùÓеķç¸ñÅäÖÃÐÅÏ¢Éú´æÎªÒ»¸öÊý×é$aStyle,ÔÚregister_globalΪonµÄÇé¿öÏÂÎÒÃÇ¿ÉÒÔÈÎÒâÌí¼Ó×Ô¼ºÏ²»¶µÄ·ç¸ñ£¬È»ºó¾Í¿ÉÒÔÔÚ×Ô¼ºÌí¼ÓµÄ·ç¸ñÖпÉÒÔËæÒâ½ç˵¿ÉÉÏ´«ÎļþÀàÐÍ¡£ |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | HTTP_ÆäËü¿ÉÒÉÐÐΪ_spring-data_mongodb_SpEL±í´ïʽעÈë[CVE-2022-22980] |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | SpringDataforMongoDBÊÇSpringDataÏîÄ¿µÄÒ»²¿ÃÅ£¬¸ÃÏîĿּÔÚΪÐÂÊý¾Ý´æ´¢ÌṩÊìϤÇÒÒ»ÖµĻùÓÚSpringµÄ±à³ÌÄ£ÐÍ£¬Í¬Ê±±£ÁôÌØ¶¨ÓÚ´æ´¢µÄÌØÐԺ͹¦Ð§¡£SpringDataMongoDBÏîÄ¿ÌṩÓëMongoDBÎĵµÊý¾Ý¿âµÄ¼¯³É¡£SpringDataMongoDBµÄÒªº¦¹¦Ð§ÊÇÒÔPOJOΪÖÐÐĵÄÄ£ÐÍ£¬ÓÃÓÚÓëMongoDBDBCollection½»»¥²¢ÇáËɱàдRepositoryÑùʽµÄÊý¾Ý·ÃÎʲ㡣 |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Imagetragick_ͼƬ´¦ÖÃÄ£¿é_ÃüÁîÖ´ÐÐ[CVE-2016-3714] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ImageMagickÊÇÒ»¿îʹÓÃÁ¿ºÜ¹ãµÄͼƬ´¦Ö÷¨Ê½£¬ºÜ¶à³§É̶¼µ÷ÓÃÁËÕâ¸ö·¨Ê½½øÐÐͼƬ´¦Ö㬰üÂÞͼƬµÄÉìËõ¡¢Çиˮӡ¡¢¸ñʽת»»µÈµÈ¡£µ«½üÀ´ÓÐÑо¿Õß·¢ÏÖ£¬µ±Óû§´«ÈëÒ»¸ö°üÂÞ¡º»ûÐÎÄÚÈÝ¡»µÄͼƬµÄʱºò£¬¾ÍÓпÉÄÜ´¥·¢ÃüÁî×¢Èë©¶´¡£ |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | TCP_ľÂíºóÃÅ_JAVAÄÚ´æÂí¹¥»÷_±äÐÎ3_Webshell·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ÄÚ´æÂí¹¥»÷ÊÇÒ»ÖÖÀûÓÃÏà¹ØÊֶε½´ïÎÞÎļþÂäµØÐ§¹ûµÄwebshell¹¥»÷ÊֶΣ¬¹¥»÷Õß¿ÉÀûÓÃÄÚ´æÂí½øÐг¤Ê±¼ä¸ßÒþ±ÎÐÔµÄwebsehll¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_OKLIite_v1.2.25_ÎļþÉÏ´«[CVE-2019-16131][CNNVD-201909-300] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | OKLiteÊÇÒ»Ì×»ùÓÚphpµÄÆóÒµ½¨Õ¾ÄÚÈݹÜÀíϵͳ£¬Æäv1.2.25°æ±¾ÒÔ¼°¸üµÍ°æ±¾ÖдæÔÚºǫ́ÎļþÉÏ´«Â©¶´£¬µÇ½ºóµÄ¹¥»÷Õß¿ÉÒÔÀûÓøÃ©¶´ÉÏ´«ÈÎÒâÎļþ£¬»ñȡĿ±êϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20220920 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | TCP_ÆäËü¿ÉÒÉÐÐΪ_дÈëjarÎļþ |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | ÔÚJAVAÖУ¬java.io.FileOutputStream¿ÉÒÔÓÃÀ´ÎļþдÈ룬¹¥»÷Õß¿ÉÀûÓøÃÀàдÈë¶ñÒâjar°ü£¬ÅäºÏÆäËü©¶´¼°ÊÖ·¨´Ó¶ø»ñȡĿµÄIPÉ豸ȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220920 |
ʼþÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ZooKeeper_δÊÚȨ·ÃÎÊ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃZooKeeper´æÔÚµÄδÊÚȨ·ÃÎÊ©¶´½øÐй¥»÷µÄÐÐΪ¡£ZooKeeperÊÇÒ»¸öÂþÑÜʽµÄ£¬¿ª·ÅÔ´ÂëµÄÂþÑÜʽӦÓ÷¨Ê½Ðµ÷·þÎñ£¬ÊÇGoogleµÄChubbyÒ»¸ö¿ªÔ´µÄʵÏÖ£¬ÊÇHadoopºÍHbaseµÄÖØÒª×é¼þ¡£ |
¸üÐÂʱ¼ä£º | 20220920 |