ÿÖÜÉý¼¶²¼¸æ-2021-11-30
°ä²¼¹¦·ò 2021-12-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_QNAP-QTS_´úÂëÖ´ÐÐ[CVE-2017-6361][CNNVD-201702-940] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬¶àýÌåÀûÓü°°²È«¼à¿ØµÈÖ°ÄÜ¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_QNAP-QTS_ºÅÁîÖ´ÐÐ[CVE-2017-6360][CNNVD-201702-941] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬¶àýÌåÀûÓü°°²È«¼à¿ØµÈÖ°ÄÜ¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐÐËÁÒâºÅÁ»ñÈ¡ÖÎÀíԱȨÏÞºÍÃô¸ÐÐÅÏ¢¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_QNAP-QTS_ºÅÁîÖ´ÐÐ[CVE-2017-6359][CNNVD-201702-942] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬¶àýÌåÀûÓü°°²È«¼à¿ØµÈÖ°ÄÜ¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚ°²È«·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡ÖÎÀíԱȨÏÞ£¬Ö´ÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | TCP_°²È«·ì϶_Hadoop_Yarn_RPCδÊÚȨ½Ó¼û·ì϶ |
°²È«ÀàÐÍ£º | ·ÇÊÚȨ½Ó¼û/ȨÏÞÈÆ¹ý |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃHadoopYarnµÄ·ì϶½øÐÐδÊÚȨ½Ó¼û£»¶ÔÓÚ8032¶³öÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬±àдÀûÓ÷¨Ê½Å²ÓÃyarnClient.getApplications()¼´¿É²é¿´ËùÓÐÀûÓÃÐÅÏ¢£»Hadoop×÷Ϊһ¸öÉ¢²¼Ê½ÍÆËãÀûÓÿò¼Ü£¬ÖÖÀàÖ°ÄÜ·±¶à£¬¶øHadoopYarn×÷ΪÆäÖ÷Ìâ×é¼þÖ®Ò»¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Apache_CouchDB_JSON_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2017-12636][CNNVD-201711-486] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÉ豸ÔÚÀûÓÃApacheCouchDBJSONÔ¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â£¬×¨Ò»ÓÚÒ×ÓÃÐԺͳÉΪ"Æëȫӵ±§webµÄÊý¾Ý¿â"¡£CouchDB»áĬÈÏ»áÔÚ5984¶Ë¿ÚÊ¢¿ªRestfulµÄAPI½Ó¿Ú£¬ÓÃÓÚÊý¾Ý¿âµÄÖÎÀíÖ°ÄÜ¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢Ìåʽ£¬JavaScript×÷Ϊ²éÎÊ˵»°£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£CouchDBѡȡ»ùÓÚErlangµÄJSON½âÎöÆ÷£¬Óë»ùÓÚJavaScriptµÄJSON½âÎöÆ÷·ÖÆç£¬CouchDBÄܹ»ÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇÉ«³Á¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ½Ó¼û½ÚÔ죬ÉõÖÁÔ̺¬°µÊ¾ÖÎÀíÓû§µÄ_admin½ÇÉ«¡£¶ñÒâ¹¥»÷ÕßÀûÓÃÕâÒ»Ö°Äܲ¢½áºÏCVE-2017-12636·ì϶£¬Äܹ»Ê¹·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý½Ó¼û·þÎñÆ÷ÉϵÄËÁÒâshellºÅÁî¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Netgear_Nighthawk_R7000δÊÚȨԶ³Ì´úÂëÖ´Ðзì϶[CVE-2021-31802] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÉ豸ÔÚÀûÓÃNetgea·ÓÉÆ÷Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£ÔÚNETGEARR7000ÉÏ´æÔÚÒ»¸öÉí·ÝÑéÖ¤ÅÔ·°²È«·ì϶¡£·ì϶ÀûÓóɹ¦ºó£¬Äܹ»rootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Primefaces_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2017-1000486][CNNVD-201801-112] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | PrimeFacesÊÇÒ»¸ö¿ªÔ´Óû§½çÃæ(UI)×é¼þ¿â£¬ÓÃÓÚ»ùÓÚJavaServerFacesµÄÀûÓ÷¨Ê½£¬ÓÉÍÁ¶úÆä¹«Ë¾PrimeTekInformatics´´½¨¡£Primefaces5.x´æÔÚÈõ¼ÓÃÜ·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ʵÏÖÔ¶³Ì´úÂëÖ´ÐС£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_D-Link_DWL-2600AP_²Ù×÷ϵͳºÅÁî×¢Èë·ì϶[CVE-2019-20499/CVE-2019-20500/CVE-2019-20501][CNNVD-202003-201/CNNVD-202003-205/CNNVD-202003-204] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | D-LinkDWL-2600APÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß½ÓÈëµãÉ豸¡£D-LinkDWL-2600AP4.2.0.15RevA°æ±¾ÖдæÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£¹¥»÷Õ߿ɽèÖú±£ÁôÅäÖÃÖ°ÄÜÀûÓø÷ì϶ִÐÐËÁÒâµÄ²Ù×÷ϵͳºÅÁî¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Terramaster_TOS_ºÅÁî×¢Èë·ì϶[CVE-2020-35665] |
°²È«ÀàÐÍ£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º | TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×Ó¼¼Êõ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾´æÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýÔÚÊÂÎñ²ÎÊýÖÐÔ̺¬makecvs.php×¢Èë²Ù×÷ϵͳºÅÁî¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_SQL_Server_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-0618][CNNVD-202002-496] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS)£¬ÊÇ´Ë¿ÌÊÀ½çÉÏ¿í·ºÊ¹ÓõÄÊý¾Ý¿âÖ®Ò»¡£¸Ã·ì϶ԴÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesÊ·ý·¢Ë;«ÐÄ»ú¹ØµÄÒªÇ󣬿ÉÀûÓô˷ì϶ÔÚ±¨±í·þÎñÆ÷·þÎñÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_´úÂëÖ´ÐÐ_ÆïÊ¿CMSÔ¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-35339][CNNVD-202102-1295] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ¼ì²â¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÆïÊ¿CMSµÄ¡°ÍøÕ¾ÓòÃû¡±¶ÔÓ¦²ÎÊý½øÐдúÂëÖ´ÐвÙ×÷£»ÆïÊ¿È˲ÅϵͳÊÇÒ»Ïî»ùÓÚPHPMYSQLΪÖ÷Ì⿪·¢µÄÒ»Ì×Ãâ·Ñ¿ªÔ´×¨ÒµÈ˲ÅÕÐÆ¸ÏµÍ³¡£ÎªÓ×ÎÒÇóÖ°ºÍÆóÒµÕÐÆ¸ÌṩÐÅÏ¢»¯½â¾ö¹æ»®,ÆïÊ¿È˲Åϵͳ¾ß±¸Ö´ÐÐЧÄܸߡ¢Ä£°åÇл»×ÔÓÉ¡¢ºó¶ÜÖÎÀíÖ°Äܽýݡ¢Ä£¿éÖ°ÄÜ׳´óµÈÌØµã¡£ |
¸üй¦·ò£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_XStream_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-26217][CNNVD-202011-1441] |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | Xstream½â×éʱ´¦ÖõÄÁ÷Ô̺¬ÀàÐÍÐÅÏ¢ÒÔ³Áд´½¨ÒÔǰ±àдµÄ¶ÔÏó¡£XStreamÒò¶ø»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐÂÊ·ý¡£¹¥»÷ÕßÄܹ»°Ñ³Ö´¦ÖùýµÄÊäÈëÁ÷²¢´úÌæ»ò×¢ÈëÄܹ»Ö´ÐÐËÁÒâshellºÅÁîµÄ¶ÔÏó¡£ |
¸üй¦·ò£º | 20211130 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐкÅÁî·ì϶ |
°²È«ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º | ÷ÈħµçÓ°·¨Ê½(MaccmsPHP)ÊÇÒ»Ì×ѡȡPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÃÀÂúµÄ׳´óÊÓÆµµçӰϵͳ¡£ÃÀÂúÖ§³Ö¶à¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬ÆëÈ«Ãâ·Ñ¿ªÔ´¡£¸Ã·ìÏ¶ÖØÒªµÄ²úÉúÔÒòÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£ |
¸üй¦·ò£º | 20211130 |


¾©¹«Íø°²±¸11010802024551ºÅ