ÿÖÜÉý¼¶²¼¸æ-2021-12-28

°ä²¼¹¦·ò 2021-12-28

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©³¨ÆðÍ·ÀûÓÃ[MS17-010][CNNVD-201703-726]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅÖ÷»ú½øÐÐMS17-010·ì϶ÀûÓõÄÐÐΪ£¬¸Ã½×¶ÎΪ·ì϶ÀûÓõijõʼ½×¶Î¡£MicrosoftWindowsÊÇ΢Èí°ä²¼µÄ¼«¶ÈÊ¢ÐеIJÙ×÷ϵͳ¡£ÈôÊǹ¥»÷ÕßÏòMicrosoft·þÎñÆ÷·¢Ë;­¾«ÐÄ»ú¹ØµÄ»ûÐÎÒªÇó°ü£¬Äܹ»»ñȡָ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬²¢ÇÒÆëÈ«½ÚÔìÖ¸±êϵͳ¡£¹¥»÷Õ߯ðÍ·½øÐÐMS17-010·ì϶ÀûÓã¬ÔÚ±¾»ú´æÔÚ·ì϶µÄÇé¿öÏ£¬ÔÚÀûÓÃʵÏÖºó¹¥»÷Õß¿ÉÄÜÆëÈ«½ÚÔìÖ÷»ú¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Spring-Data-REST-PATCHÒªÇó_Ô¶³ÌÖ´ÐдúÂë[CVE-2017-8046]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

2017Äê9ÔÂ21ÈÕ£¬Ê¢ÐеÄJava¿ò¼Üspring±»·¢ÏÖÒ»¸ö¸ßΣ·ì϶£¬·ì϶CVE±àºÅΪCVE-2017-8046¡£ºÚ¿ÍÄܹ»ÀûÓø÷ì϶Զ³ÌÖ´ÐкÅÁʹÓÃÁËspring¿ò¼ÜµÄÒµÎñ´æÔڸ߰²È«·çÏÕ¡£SpringDataRestÊÇSpringData¿ò¼ÜµÄÆäÖÐÒ»¸ö×é¼þ£¬SpringDataRest¿É¹¹½¨RestWeb£¬SpringDataRest¶ÔPATCH²½Öè´¦Öò»µ±£¬µ¼Ö¹¥»÷Õß¿ÉÄÜÀûÓÃJSONÊý¾ÝÔì³ÉRCE¡£ÐÔÖÊ»¹ÊÇÓÉÓÚSpringµÄSPEL½âÎöµ¼ÖµÄRCE¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Intellian_Satellian_Aptus_WebÔ¶³Ì´úÂëÖ´ÐÐ[CVE-2020-7980]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

Intellian Satellian Aptus Web ÊÇÒ»¸ö½ÚÔį̀ϵͳ¡£ÔÚIntellian Aptus Web 1.24 ֮ǰµÄ°æ±¾ÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý JSON Êý¾ÝÖÐµÄ Q ×Ö¶ÎÏò/cgi-bin/libagent.cgi Ö´ÐÐËÁÒâ OS ºÅÁî¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_ºÅÁîÖ´ÐÐ_Alcatel-Lucent_OmniPCX_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2007-3010][CNNVD-200709-257]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃAlcatelR7.1°æ±¾ÒÔǰµÄ·ì϶½øÐкÅÁîÖ´ÐУ»Alcatel_OmniPCXEnterpriseÊÇÒ»ÖÖÕë¶Ô´óÖÐÐÍÆóÒµ¡¢±ö¹Ý¡¢ºô½ÐÖÐÐĵɽ»»¥Ê½Í¨Ñ¶½â¾ö¹æ»®¡£¸Ã½â¾ö¹æ»®½«´«Í³µÄµç»°Ö°ÄܺͶԻùÓÚÒòÌØÍøµÄÓïÒôͨѶ¼°¶àýÌåͨѶµÄÖ§³ÖÏà½áºÏ¡£AlcatelOmniPCXEnterpriseÊÇ»ùÓÚÒµ½ç³ß¶ÈµÄÊ¢¿ªÐÍ¡¢É¢²¼Ê½Í¨ÕÛ·þÎñÆ÷£¬ºÏÓÃÓÚ´óÖÐÐÍÆóÒµµÄͨѶҵÎñ¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ÐÅϢй¶·ì϶[CVE-2018-6910][CNNVD-201802-949]

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

DesdevDedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈݰ䲼¡¢±à×ë¡¢ÖÎÀí¼ìË÷µÅ×ÚÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£DesdevDedeCMS5.7°æ±¾ÖдæÔÚÐÅϢй¶·ì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý¶Ôinclude/downmix.inc.php»òinc/inc_archives_functions.phpÎļþ·¢ËͽÓÒªÇóÀûÓø÷ì϶»ñÈ¡ÆëÈ«õè¾¶¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Apache_Druid_LoadData_ËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2021-36749][CNNVD-202109-1676]

°²È«ÀàÐÍ£º

Îļþ¶ÁÈ¡

ÊÂÎñÃèÊö:

ApacheDruidÊÇÒ»¸öʵʱ³½ÎöÐÍÊý¾Ý¿â£¬Ö¼ÔÚ¶Ô´óÐÍÊý¾Ý¼¯½øÐм±¾çµÄ²éÎÊ·ÖÎö¡£ÔÚApacheDruidϵͳÖУ¬InputSourceÓÃÓÚ´Óij¸öÊý¾ÝÔ´¶ÁÈ¡Êý¾Ý¡£ÓÉÓÚûÓжÔÓû§¿É¿ØµÄHTTPInputSource×öÏÞ¶È£¬ApacheDruidÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§ÒÔDruid·þÎñÆ÷¹ý³ÌµÄȨÏÞ´ÓÖ¸¶¨Êý¾ÝÔ´¶ÁÈ¡Êý¾Ý£¬Ô̺¬±¾µØÎļþϵͳ¡£¹¥»÷Õß¿Éͨ¹ý½«ÎļþURL´«µÝ¸øHTTPInputSourceÀ´ÈƹýÀûÓ÷¨Ê½¼¶´ËÍâÏÞ¶È¡£ÓÉÓÚApacheDruidĬÈÏÇé¿öϲ»×ãÊÚȨÈÏÖ¤£¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâÒªÇó£¬ÔÚδÊÚȨÇé¿öÏÂÀûÓø÷ì϶¶ÁÈ¡ËÁÒâÎļþ£¬×îÖÕµ¼Ö·þÎñÆ÷Ãô¸ÐÐÅϢй¶¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_WordPress_δÊÚȨ½Ó¼û[CVE-2019-17671][CNNVD-201910-1180]

°²È«ÀàÐÍ£º

·ÇÊÚȨ½Ó¼û/ȨÏÞÈÆ¹ý

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÀûÓÃWordPress5.2.3ÒÔǰµÄ·ì϶£¬½øÐÐδÊÚȨµÄ°ÂÃØÎļþ½Ó¼û

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ǰ̨ËÁÒâÓû§ÃÜÂëÅú¸Ä·ì϶

°²È«ÀàÐÍ£º

Âß¼­/Éè¼ÆÃýÎó

ÊÂÎñÃèÊö:

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DedeCMSÔÚÓû§ÃÜÂë³ÁÖÃÖ°ÄÜ´¦£¬php´æÔÚÈõÀàÐͱÈÁ¦£¬µ¼ÖÂÈôÊÇÓû§Ã»ÓÐÉèÖÃÃܱ£ÎÊÌâµÄÇé¿öÏ£¬¹¥»÷ÕßÄܹ»ÈƹýÑéÖ¤Ãܱ£ÎÊÌ⣬ֱ½ÓÅú¸ÄÃÜÂë(ÖÎÀíÔ¹ØË»§Ä¬Èϲ»ÉèÖÃÃܱ£ÎÊÌâ)¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ǰ̨ÎļþÉÏ´«·ì϶

°²È«ÀàÐÍ£º

ÎļþÉÏ´«

ÊÂÎñÃèÊö:

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DedeCmsÔÚÓû§°ä²¼ÎÄÕÂÉÏ´«Í¼Æ¬´¦´æÔÚÎļþÉÏ´«·ì϶£¬¸Ã·ì϶ԴÓÚ¶ÔÉÏ´«Îļþºó׺¼ì²â²»ÑϽ÷£¬¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ½ÚÔìÖ÷»ú¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Phpcms_install.php_ǰ̨Getshell

°²È«ÀàÐÍ£º

ÅäÖò»µ±/ÃýÎó

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ip¿ÉÄÜ´æÔÚÔÚÀûÓÃÖ÷ÕÅipµÄPhpcmsÉÏδɾ³ýµÄinstall.php½øÐжñÒâ¹¥»÷µÄÐÐΪ£¬Ä¿Ç°¹æ¶¨ÎÞ·¨ÕýÈ·ÅжÏÊÇ·ñΪ¶ñÒâ¹¥»÷¡£PHPCMSÊÇ¿ªÔ´µÄÕûվϵͳ¡£PHPCMS´æÔÚPHPCMS_v2008_preview.php×¢Èë·ì϶£¬¹¥»÷ÕßÀûÓô˷ì϶ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡Êý¾Ý¿âºÍÖÎÀíԱȨÏÞ¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ADSelfService-PlusδÊÚȨ_ËÁÒâ´úÂëÖ´ÐÐ[CVE-2021-40539][CNNVD-202109-330]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

ZOHOManageEngineADSelfServicePlusÊÇÃÀ¹ú׿ºÀ£¨ZOHO£©¹«Ë¾µÄÕë¶ÔActiveDirectoryºÍÔÆÀûÓ÷¨Ê½µÄ¼¯³Éʽ×ÔÖ÷ÃÜÂëÖÎÀíºÍµ¥µãµÇ¼½â¾ö¹æ»®¡£ZohoManageEngineADSelfServicePlus6113°æ±¾¼°¸üÔç°æ±¾´æÔÚÊÚȨÎÊÌâ·ì϶£¬¸Ã·ì϶ԴÓÚÈí¼þºÜÈÝÒ×ÈÆ¹ýRESTAPIÈÏÖ¤£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_Spring-api-actuatorÓйØÎļþ_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

SpringBoot¹Ù·½ÌṩÁËspring-boot-starter-actuator³¡¾°Æô¶¯Æ÷ÓÃÓÚϵͳµÄ¼à¿ØÖÎÀí£¬Äܹ»Í¨¹ýHTTP£¬JMX£¬SSHºÍ̸À´½øÐвÙ×÷£¬×Ô¶¯µÃµ½É󼯡¢½¡È«¼°Ö¸±êÐÅÏ¢µÈ¡£ÓйØÎļþ½ÔΪÃô¸ÐÎļþ£¬Î´×ö½Ó¼ûȨÏÞ½ÚÔ콫µ¼ÖÂÐÅϢй¶¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_Swagger-api¹¤¾ß_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢»ùÓÚYAML¡¢JSON˵»°µÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£©£¬ÓйØÎļþ¼Ð±»½Ó¼ûÓÐÐÅϢй¶·çÏÕ¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Seowon-Intech-SWC-9100-Routers_ºÅÁîÖ´ÐÐ[CVE-2013-7179][CNNVD-201402-022]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

SeowonIntechSWC-9100RoutersÊǺ«¹úÈðÔªÒóÌØ£¨SeowonIntech£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£SeowonIntechSWC-9100·ÓÉÆ÷ÖеÄcgi-bin/diagnostic.cgiÎļþÖеÄpingÖ°ÄÜÖдæÔÚÊäÈëÑéÖ¤·ì϶¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú¡®ping_ipaddr¡¯²ÎÊýÖеÄshellÔª×Ö·ûÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÖ÷ÓòÃû½âÎöÒªÇó7

°²È«ÀàÐÍ£º

ÍÚ¿óÈí¼þ

ÊÂÎñÃèÊö:

¼ì²âµ½¿ÉÒÉÍÚ¿óľÂíÊÔͼÏνÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂí³¢ÊÔÏνӿ󳨣¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬¿÷ËðCPU×ÊÔ´¡£ÈôÊÇΪÓû§Õý³£½Ó¼û¿ó³ØÖ÷Ò³£¬ÔòºöÂÔ¸ÃÊÂÎñ¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_MicrosoftOffice_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-40444][CVE-2021-40444][CNNVD-202109-350]

°²È«ÀàÐÍ£º

ÎļþÏÂÔØ

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipµØµãµÄÖ÷»úÔÚÀûÓÃCVE-2021-40444ÏÂÔØ¶ñÒⷨʽ£¬ÊÂÎñ¼ì²âÏìÓ¦°üÌØµã¡£CVE-2021-40444ÊÇÒ»¸öÔÚ2021Äê9Ô±»±¬³öµÄÔÚÒ°ÀûÓõķì϶£¬Óû§Ö»±ØÒªË«»÷Ö´ÐÐdocxÎļþ»òʹÓÃie½Ó¼û¶ñÒâÍøÕ¾£¬¼´¿ÉÖ´ÐжñÒⷨʽ¡£¸Ã·ì϶λÓÚWindowsµÄMSHML×é¼þ£¬MSHML×é¼þÊÇ΢ÈíIEä¯ÀÀÆ÷µÄÅŰæÒýÇæ£¬Ò²Äܹ»ÔÚoffice·¨Ê½ÖгöÏÖwebÒ³Ãæ¡£MSHTMLÌṩÁËCOM½Ó¿Ú£¬ÈκÎÖ§³ÖCOMµÄ»·¾³¶¼Äܹ»Í¨¹ý¸Ã×é¼þ½Ó¼û¡¢±à×ëÍøÒ³¡£

¸üй¦·ò£º

20211228


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈÆ¹ýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓá£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈÆ¹ýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓá£

¸üй¦·ò£º

20211228