ÿÖÜÉý¼¶Í¨¸æ-2023-02-28

Ðû²¼Ê±¼ä 2023-02-28

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_ÃüÁîÖ´ÐÐ_GLPI_htmLawedTest.php

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃGLPIÖÐhtmLawedTest.php´¦µÄ©¶´£¬½øÐÐÔ¶³ÌÈÎÒâÃüÁîÖ´ÐС£GLPIÊǸöÈË¿ª·¢ÕßµÄÒ»¿î¿ªÔ´ITºÍ×ʲú¹ÜÀíÈí¼þ¡£¸ÃÈí¼þÌṩ¹¦Ð§È«ÃæµÄIT×ÊÔ´¹ÜÀí½Ó¿Ú£¬Äã¿ÉÒÔÓÃËüÀ´½¨Á¢Êý¾Ý¿âÈ«Ãæ¹ÜÀíITµÄµçÄÔ£¬ÏÔʾÆ÷£¬·þÎñÆ÷£¬´òÓ¡»ú£¬ÍøÂçÉ豸£¬µç»°£¬ÉõÖÁÎø¹ÄºÍÄ«ºÐµÈ¡£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_δÊÚȨ·ÃÎÊ_Apache_AXIS_AdminService

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃApacheAxisδÊÚȨ·ÃÎÊ©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£ApacheAxisÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÎï°üÂÞÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API£¬ÒÔÉú³ÉºÍ²¿ÊðWeb·þÎñÓ¦Óá£Â©¶´±¾ÖÊÊǹÜÀíÔ±¶ÔAdminServiceµÄÅäÖôíÎó¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬¹¥»÷Õß¿ÉÒԽṹWebServiceµ÷ÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬Զ³ÌÀûÓÃAdminService½Ó¿Ú½øÐÐWebServiceÐû²¼£¬ÔٴηÃÎÊÉú³ÉµÄWebService½Ó¿Ú£¬´«ÈëÒªÖ´ÐеÄÃüÁ¾Í¿ÉÒÔ½øÐÐÔ¶³ÌÃüÁîÖ´ÐЩ¶´µÄÀûÓá£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_IBM_Aspera_Faspex[CVE-2022-47986]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

IBMAsperaFaspexÊÇÒ»¸ö»ùÓÚIBMAspera¸ßËÙ´«Êä·þÎñÆ÷¹¹½¨µÄÎļþ½»»»Ó¦Ó÷¨Ê½£¬×÷Ϊ¼¯Öд«Êä½â¾ö·½°¸¡£½èÖú»ùÓÚWebµÄGUI£¬FaspexΪFASP¸ßËÙ´«ÊäÌṩÁ˸߼¶¹ÜÀíÑ¡ÏÒÔÆ¥ÅäÏà¹ØµÄÊÂÇéÁ÷³Ì¡£ÓÉÓÚYAML·´ÐòÁл¯È±ÏÝ£¬IBMAsperaFaspex¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂ롣ͨ¹ý·¢ËÍÌرðÖÆ×÷µÄ¹ýʱAPIµ÷Ó㬹¥»÷Õß¿ÉÒÔÀûÓôË©¶´ÔÚϵͳÉÏÖ´ÐÐÈÎÒâ´úÂë¡£Ó°Ïì°æ±¾£ºFaspex<=4.4.2

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_logging.config

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/evn½Ó¿Úͨ¹ýlogging.config²ÎÊýʵÑéÔ¶³Ì´úÂëÖ´ÐС£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØϵͳÊý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØºÜ¶àºÜ¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬¿ÉÒÔ¼ì²ìÓ¦ÓÃÅäÖõÄÏêϸÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20230228

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Discuz_X_uc_center

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Discuz!MLϵͳÖУ¬Í¨¹ýºǫ́ÐÞ¸ÄUcenterÊý¾Ý¿âÁ¬½ÓÐÅÏ¢£¬¿É½«¶ñÒâ´úÂëдÈëconfig/config_ucenter.phpÎļþÖУ¬µ¼Ö´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Discuz!X3.4

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Discuz!MLϵͳ°²×°ºóδµÇ½ºǫ́ʱ£¬¿ÉÀûÓÃÎļþɾ³ý©¶´É¾µôinstall.lockÎļþ£¬Èƹý¶Ô°²×°Íê³ÉµÄÅжÏÄܹ»ÔÙ½øÐа²×°µÄ¹ý³Ì£¬È»ºó½«¶ñÒâ´úÂëдÈëÅäÖÃÎļþÖдӶøÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_Phpcms:V9.5.8_ºǫ́¹ÜÀí

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃCMS-Phpcms:V9.5.8ºǫ́ÈÎÒâ´úÂëÖ´ÐЩ¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬¸Ã©¶´ÀûÓÃcontent.phpÎļþ½á¹¹¶ñÒâpayload£¬´Ó¶øÔì³É´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_´úÂëÖ´ÐÐ_SpamTitanÍø¹Ø[CVE-2020-11699][CNNVD-202009-1082]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

SpamTitanÍø¹ØÊǹ¦Ð§Ç¿´óµÄ·´À¬»øÓʼþÉ豸£¬ËüΪÍøÂç¹ÜÀíÔ±ÌṩÁ˹㷺µÄ¹¤¾ßÀ´¿ØÖÆÓʼþÁ÷²¢·ÀÖ¹Óк¦µÄµç×ÓÓʼþºÍ¶ñÒâÈí¼þ¡£ÓÉÓÚ´æÔÚ´úÂëȱÏÝ£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâpayload£¬Ê¹µÃÄ¿±êÖ÷»úÖ´ÐжñÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_Õì²ìɨÃè_ɨÃèÆ÷_DisBuster

Äþ¾²ÀàÐÍ£º

Äþ¾²É¨Ãè

ʼþÃèÊö£º

DisBusterÊÇÉø͸²âÊÔ¹ý³ÌÖг£ÓõÄɨÃ蹤¾ß£¬¿ÉÒÔ×Ô½ç˵¼ÓÔØ×Ô½ç˵×Öµä¶ÔÄ¿±ê½øÐÐĿ¼»òÒ³ÃæɨÃèºÍ±¬ÆÆ¡£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Weblogic_ForeignOpaqueReference×é¼þ_JNDI×¢Èë_´úÂëÖ´ÐÐ[CVE-2023-21839]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨£¬ÓÃÓÚÔÚµ±µØºÍÔƶ˿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÓ¦Ó÷¨Ê½£¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£ÓÉÓÚForeignOpaqueReferenceÀà´æÔÚÄþ¾²ÎÊÌ⣬CVE-2023-21839©¶´ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3/IIOPЭÒéÍøÂç·ÃÎʲ¢ÆÆ»µÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½Ó¹Ü»òÃô¸ÐÐÅϢй¶¡£Ó°Ï췶Χ£ºOracleWebLogicServer12.2.1.3.0OracleWebLogicServer12.2.1.4.0OracleWebLogicServer14.1.1.0.0

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

TCP_Äþ¾²Â©¶´_Apache_Log4j2_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2021-44228][CNNVD-202112-799]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ApacheLog4j2ÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£ÔÚApacheLog4j22.15.0_rc1֮ǰµÄ2.x°æ±¾ÖдæÔÚÄþ¾²Â©¶´¡£¹¥»÷Õß¿ÉÀûÓø鶴Զ³ÌÖ´ÐÐÈÎÒâ´úÂë

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_©¶´ÀûÓÃ_SQL×¢Èë_Django_kind_lookup_name[CVE-2022-34265][CNNVD-202207-347]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

DjangoÊÇÒ»¸ö»ùÓÚPythonµÄ¿ªÔ´WebÓ¦Óÿò¼Ü¡£Django´æÔÚÒ»¸öSQL×¢È멶´£¨CVE-2022-34265£©¡£ÔÚÊÜÓ°ÏìµÄDjango°æ±¾£¨3.2.14¡¢4.0.6֮ǰµÄ°æ±¾£©ÖУ¬¿ÉÒÔͨ¹ýͨ±¨¶ñÒâÊý¾Ý×÷Ϊkind/lookup_nameµÄÖµ£¬Èç¹ûÓ¦Ó÷¨Ê½ÔÚ½«ÕâЩ²ÎÊýͨ±¨¸øTrunc()ºÍExtract()Êý¾Ý¿âº¯Êý£¨ÈÕÆÚº¯Êý£©Ö®Ç°Ã»Óо­¹ýÊäÈë¹ýÂË»òתÒ壬ÔòÈÝÒ×Êܵ½SQL×¢Èë¹¥»÷¡£Í¨¹ýÀûÓôË©¶´£¬µÚÈý·½¿ÉÒÔÏòÊý¾Ý¿â·¢ËÍÃüÁîÒÔ·ÃÎÊδ¾­ÊÚȨµÄÊý¾Ý»òɾ³ýÊý¾Ý¿âµÈ¶ñÒâÐÐΪ¡£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

TCP_©¶´ÀûÓÃ_·´ÐòÁл¯_Weblogic_T3ЭÒé[CVE-2020-14756][CVE-2020-14756/CVE-2021-2394]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨£¬ÓÃÓÚÔÚµ±µØºÍÔƶ˿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÓ¦Ó÷¨Ê½£¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2020-2555©¶´¿ÉÒÔÈƹýºÚÃûµ¥Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»Äþ¾²µÄextractÒªÁ죬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç·ÃÎʲ¢ÆÆ»µÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½Ó¹Ü»òÃô¸ÐÐÅϢй¶¡£Ó°Ï췶Χ£ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_jolokia_logback_Ô¶³Ì´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃActuatorµÄ/jolokia½Ó¿Úµ÷ÓÃch.qos.logback.classic.jmx.JMXConfiguratorÀàµÄreloadByURLÒªÁìÉèÖÃÍⲿÈÕÖ¾ÅäÖÃurlµØÖ·¡£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØϵͳÊý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØºÜ¶àºÜ¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬¿ÉÒÔ¼ì²ìÓ¦ÓÃÅäÖõÄÏêϸÐÅÏ¢¡£JolokiaÔÊÐíͨ¹ýHTTP·ÃÎÊËùÓÐÒÑ×¢²áµÄMBean£¬Í¬Ê±¿ÉÒÔʹÓÃURLÁгöËùÓпÉÓõÄMBeans²Ù×÷¡£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÇëÇó

Äþ¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂíʵÑéÁ¬½Ó¿ó³Ø£¬Êܺ¦Ö÷»ú±äÂý¡£

¸üÐÂʱ¼ä£º

20230228

 

ʼþÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_WebLogic_·´ÐòÁл¯Â©¶´[CVE-2018-3252][CNNVD-201810-843]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWeblogic½á¹¹¶ñÒâ·´ÐòÁдúÂëÖ´ÐÐÈÎÒâÃüÁOracleWeblogicServerÊÇÓ¦Ó÷¨Ê½·þÎñÆ÷¡£WeblogicÓ¦Ó÷þÎñÆ÷µÄApacheConnectorÄ£¿éÖеÄmod_wlδ¶ÔÓû§Ìá½»µÄÊäÈëÊý¾Ý½øÐÐÕýÈ·¼ì²é£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴½øÐлº³åÇøÒç³ö¹¥»÷£¬¿Éµ¼Ö¾ܾø·þÎñ»òÈÎÒâ´úÂëÖ´Ðй¥»÷¡£¹¥»÷Õß¿ÉÒÔÌá½»°üÂÞ³¬³¤Êý¾ÝµÄPOSTÇëÇó´¥·¢´Ë©¶´£¬¾«ÐĹ¹½¨Ìá½»Êý¾Ý¿Éµ¼ÖÂÒÔÓ¦Ó÷¨Ê½È¨ÏÞÖ´ÐÐÈÎÒâÖ¸Á»ñµÃ·þÎñÆ÷µÄ¿ØÖÆȨ¡£

¸üÐÂʱ¼ä£º

20230228