ÿÖÜÉý¼¶²¼¸æ-2022-05-10
°ä²¼¹¦·ò 2022-05-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_GoAhead_Ô¶³ÌºÅÁîÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | GoAheadÊÇÒ»¸ö¿ªÔ´(óÒ×Ðí¿É)¡¢µ¥Ò»¡¢ÇáÇÉ¡¢Ö°ÄÜ׳´ó¡¢Äܹ»ÔÚ¶à¸öƽ̨ÔËÐеÄWebServer£¬¶àÓÃÓÚǶÈëʽϵͳ¡¢ÖÇÄÜÉ豸¡£ÆäÖ§³ÖÔËÐÐASP¡¢JavascriptºÍ³ß¶ÈµÄCGI·¨Ê½£¬Õâ¸ö·ì϶¾Í³Ê´Ë¿ÌÔËÐÐCGI·¨Ê½µÄʱ³½¡£GoAheadÔڽӹܵ½ÒªÇóºó£¬½«»á´ÓURL²ÎÊýÖÐÈ¡³ö¼üºÍÖµ×¢²á½øCGI·¨Ê½µÄ»·¾³±äÁ¿£¬ÇÒÖ»¹ýÂËÁËREMOTE_HOSTºÍHTTP_AUTHORIZATION¡£ÎÒÃÇ¿ÉÄܽÚÔì»·¾³±äÁ¿£¬¾ÍÓкö๥»÷·½Ê½¡£ºÃ±ÈÔÚLinuxÖУ¬LD_¿ªÍ·µÄ»·¾³±äÁ¿ºÍ¶¯Ì¬Á´½Ó¿âÓйأ¬ÈçLD_PRELOADÖÐÖ¸¶¨µÄ¶¯Ì¬Á´½Ó¿â£¬½«»á±»×Ô¶¯¼ÓÔØ£»LD_LIBRARY_PATHÖ¸¶¨µÄõè¾¶£¬·¨Ê½»áÈ¥ÆäÖÐѰÕÒ¶¯Ì¬Á´½Ó¿â¡£ÎÒÃÇÄܹ»Ö¸¶¨LD_PRELOAD=/proc/self/fd/0£¬ÓÉÓÚ/proc/self/fd/0Êdz߶ÈÊäÈ룬¶øÔÚCGI·¨Ê½ÖУ¬POSTÊý¾ÝÁ÷¼´Îª³ß¶ÈÊäÈëÁ÷¡£ÎÒÃDZàÒëÒ»¸ö¶¯Ì¬Á´½Ó¿â£¬½«Æä·ÅÔÚPOSTBodyÖУ¬·¢Ë͸øhttp://target/cgi-bin/index?LD_PRELOAD=/proc/self/fd/0£¬CGI¾Í»á¼ÓÔØÎÒÃÇ·¢Ë͵Ķ¯Ì¬Á´½Ó¿â£¬Ôì³ÉÔ¶³ÌºÅÁîÖ´Ðзì϶¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_FreePBX_Ô¶³ÌºÅÁîÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | FreePBXÊÇÒ»¸ö×î׳´óµÄGUI£¨»ùÓÚÍøÒ³µÄ£©ÅäÖÃAsteriskµÄ¹¤¾ß£¬ÔÚÆä13ºÍ14°æ±¾´æÔÚ°²È«·ì϶£¬Ö÷»úÓб»Ö´ÐÐËÁÒâϵͳºÅÁîµÄ·çÏÕ¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_WordPress_Levo_Slideshow_2.3_ËÁÒâÎļþÉÏ´«·ì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | WordPressLevo-Slideshow²å¼þ2.3°æ±¾´æÔÚÎļþÉÏ´«·ì϶£¬¸Ã·ì϶ԴÓÚ¶ÔÉÏ´«Îļþºó׺¼ì²â²»ÑϽ÷£¬¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ½ÚÔìÖ÷»ú¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_CA_Privileged_Access_Manager_ºÅÁî×¢Èë·ì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | CAPrivilegedAccessManager2.8.2¼°¸üÔç°æ±¾ÖдæÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÔìÒªÇóÖ´ÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_PixelStor_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2020-6756][CNNVD-202001-346] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | RasilientPixelStor5000K:4.0.1580-20150629£¨KDI°æ±¾£©ÖеÄlanguageOptions.phpÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýlang²ÎÊýÔ¶³ÌÖ´ÐкÅÁî¡£ |
¸üй¦·ò£º | 20220510 |

ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_PmWiki_PageListSort_Ô¶³Ì´úÂë×¢Èë·ì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | PmWikiÊÇÒ»ÖÖ»ùÓÚWiki¼¼ÊõµÄ¿ªÔ´¶àÈ˺Ï×÷Õ¾µã´´½¨ºÍÊØ»¤¹¤¾ß¡£PmWiki2.0.0µ½2.2.34°æ±¾ÖдæÔÚÔ¶³ÌPHP´úÂë×¢Èë·ì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÊÜÓ°ÏìµÄÀûÓ÷¨Ê½¸ßµÍÎÄÖÐ×¢ÈëºÍÖ´ÐÐËÁÒâPHP´úÂ룬Õâ¿ÉÄÜ»áÍÆ½ø¹¥»÷Õß²Ù¿ØÀûÓ÷¨Ê½ºÍµ×²ãϵͳ£¬»òÕßÔì³ÉÆäËûµÄ¹¥»÷¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Basilic1.5.14-diff.php_Ô¶³ÌºÅÁîÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | BasilicÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚÊÜÓ°ÏìÀûÓ÷¨Ê½¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâºÅÁî¡£Basilic1.5.14°æ±¾ÖдæÔÚ·ì϶£¬ÆäËû°æ±¾Ò²¿ÉÄÜÊܵ½Ó°Ïì¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_WAN-Emulator-v2.3_ËÁÒâºÅÁîÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | WANEmulatorÊǹãÓòÍøÂç·ÂÕÕÆ÷¡£WANEmulator´æÔÚ·¸·¨½Ó¼û·ì϶£¬dosu¶þ½øÔìÎļþ×°ÖÃÁËsetuidrootºó¿É´¥·¢´Ë·ì϶£¬µ¼Ö±¾µØ¹¥»÷Õß»ñÈ¡rootȨÏÞ¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_ºÃÊÓͨÊÓÆµ»áÒéϵͳ_ËÁÒâÎļþÏÂÔØ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ºÃÊÓͨÊÓÆµ»áÒéÆóÒµ°æ·þÎñÆ÷ÖÎÀíºó¶Ü´æÔÚËÁÒâÎļþÏÂÔØ·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬¹©¸øḚ́䲼Á˰²È«²¼¸æ¼°Óйز¹¶¡ÐÅÏ¢£¬½¨¸´ÁË´Ë·ì϶¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Ruckus_IoT_Controller_Éí·ÝÑéÖ¤ÈÆ¹ý·ì϶[CVE-2020-26879][CNNVD-202010-1425] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | RuckusIoTController£¨<=1.5.1.0.21°æ±¾£©ÖдæÔÚÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶¡£¸Ã·ì϶ÊÇÓÉÓÚ¶Ô¾«ÐÄÉè¼ÆµÄHTTPÒªÇó´¦Öò»µ±Ôì³ÉµÄ£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýÏòÖ¸±ê·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄHTTPÒªÇóÀ´ÀûÓø÷ì϶£¬³É¹¦ÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Vtiger-CRM-×°Öþ籾_δÊÚȨ³Á×° |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | VtigerCRMÊÇÃÀ¹úVtiger¹«Ë¾µÄÒ»Ì×»ùÓÚSugarCRM¿ª·¢µÄ¿Í»§¹ØÏµÖÎÀíϵͳ£¨CRM£©£¬ËüÌṩÖÎÀí¡¢ÍøÂç¡¢·ÖÎö¿Í»§ÐÅÏ¢µÈÖ°ÄÜ¡£InstallModuleÊÇÆäÖеÄÒ»¸ö×°ÖÃÄ£¿é¡£VtigerCRM6.0°æ±¾µÄInstallÄ£¿éÖеÄviews/Index.php¾ç±¾ÖдæÔÚ°²È«·ì϶£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·Ï޶ȽӼûȨÏÞ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËÍÔ̺¬X-Requested-WithHTTPÍ·ÉèÖõÄÒªÇóÀûÓø÷ì϶³Á×°ÀûÓ÷¨Ê½¡£ |
¸üй¦·ò£º | 20220510 |
ÊÂÎñÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_systeminfo_Ô¶³ÌºÅÁîÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳºÅÁîµÄ»ØÏÔÐÅÏ¢£¬×¢Ã÷Ö÷»úÓпÉÄÜÒѾ±»ÈëÇÖ£¬ÇÒ¹¥»÷ÕßÓµÓÐÖ´ÐÐϵͳºÅÁîµÄȨÏÞ¡£ |
¸üй¦·ò£º | 20220510 |


¾©¹«Íø°²±¸11010802024551ºÅ