ÿÖÜÉý¼¶²¼¸æ-2022-08-05

°ä²¼¹¦·ò 2022-08-05

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_GITEA_1.4.0_Îļþ¶ÁÈ¡

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

GiteaÊÇ´ÓgogsÑÜÉú³öµÄÒ»¸ö¿ªÔ´ÏîÄ¿£¬ÊÇÒ»¸öÀàËÆÓÚGithub¡¢GitlabµÄ¶àÓû§Git²Ö¿âÖÎÀíÆ½Ì¨¡£Æä1.4.0°æ±¾ÖÐÓÐÒ»´¦Âß¼­ÃýÎ󣬵¼ÖÂδÊÚȨÓû§Äܹ»´©Ô½Ä¿Â¼£¬¶ÁдËÁÒâÎļþ£¬×îÖÕµ¼ÖÂÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÌìÈÚÐÅ_ÉÏÍøÐÐΪÖÎÀíϵͳ_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃÌìÈÚÐÅÉÏÍøÖÎÀíϵͳµÄ·ì϶½øÐÐËÁÒâºÅÁîÖ´ÐС£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_H3C_CVM_ËÁÒâÎļþÉÏ´«

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

H3CCVM(ÔÆÐé¹¹»¯ÖÎÀíϵͳ)´æÔÚÒ»¸öǰ̨ËÁÒâÎļþÉÏ´«·ì϶¡£ÓÉÓÚδ¶Ô´«²Î½øÐкϷ¨ÐÔУÑ飬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹ØÊý¾Ý°üÉÏ´«ËÁÒâÀàÐÍÎļþ¡£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PbootCMS-parserIfLabel_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

PbootCMSÊÇÒ»¿î¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾¿ª·¢½¨ÉèÖÎÀíϵͳ¡£ÆäÖеÄparserIfLabel²½Öè´æÔÚÄ£°å×¢Èë·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶»ñȡָ±êÖ÷»úȨÏÞ¡£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_ºì·«Ò½ÁÆÔÆ_OA_SQL×¢Èë

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

¹ãÖݺ췫¿Æ¼¼ÓÐÏÞ¹«Ë¾£¨ÒÔϼò³Æ£ººì·«¿Æ¼¼£©ÊÇÊ®ÐÛʦ¹¤¼¯ÍÅÖ®Ò»£¬ÊÇÖйú´¬²°¼¯ÍÅÓÐÏÞ¹«Ë¾ÆìϹ㴬¹ú¼ÊÓÐÏÞ¹«Ë¾¿Ø¹ÉµÄ¸ßм¼ÊõÆóÒµ¡£ºì·«iOfficeÒ½Ôº°æ´æÔÚSQL×¢Èë·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Êý¾Ý¿âÃô¸ÐÐÅÏ¢¡£

¸üй¦·ò£º

20220805

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Roxy-WI-options.py_ºÅÁîÖ´ÐÐ[CVE-2022-31137][CNNVD-202207-676]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Roxy-WIÊÇÓÃÓÚÖÎÀíHaproxy¡¢NginxºÍKeepalived·þÎñÆ÷µÄWeb½çÃæ¡£ÆäÖÐ6.1.1.0֮ǰµÄoptions.py´æÔÚ·ì϶£¬¹¥»÷Õß¿ÉÄÜÔÚδÊÚȨµÄÇé¿öÏÂÖ´ÐÐËÁÒâºÅÁ½ÚÔìϵͳȨÏÞ

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢E-office-do_excel.php_ÎļþдÈë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£ÆäÖÐ/do_excel.php½Ó¿Ú´æÔÚ·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶дÈë¶ñÒâÎļþ£¬Ö²Èëwebshell£¬»ñȡָ±êϵͳȨÏÞ¡£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_º£¿µÍþÊÓ×ÛºÏÔËÓªÖÎÀíÆ½Ì¨_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

º£¿µÍþÊÓ×ÛºÏÔËÓªÖÎÀíÆ½Ì¨Ô̺¬fastjson×é¼þ£¬·¢ËͶñÒâjsonÊý¾ÝÄܹ»µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÁéͨOA_·ÇÊÚȨ½Ó¼û

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ÁéͨOAÊÇÒ»Ìװ칫ϵͳ¡£ÓÉÓÚÁéͨOAÖÐheader.inc.php´æÔÚ·ì϶£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýµÇ½ÏÞ¶È£¬µ¼ÖÂδÊÚȨ½Ó¼û¡£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-061Ô¶³ÌºÅÁîÖ´Ðй¥»÷[CVE-2020-17530/CVE-2021-31805][CNNVD-202012-449/CNNVD-202204-3223]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâµÄÒªÇó£¬Òý·¢OGNL±í°×ʽ½âÎö£¬´Ó¶ø´¥·¢Ô¶³Ì´úÂëÖ´Ðзì϶¡£

¸üй¦·ò£º

20220805

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Laravel_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2021-3129]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

LaravelÊÇÒ»Ì×¼ò½à¡¢¿ªÔ´µÄPHPWeb¿ª·¢¿ò¼Ü£¬Ö¼ÔÚʵÏÖWebÈí¼þµÄMVC¼Ü¹¹¡£µ±Laravel¿ªÆôÁËDebugģʽʱ£¬ÓÉÓÚLaravel×Ô´øµÄIgnition×é¼þ¶Ôfile_get_contents()ºÍfile_put_contents()º¯ÊýµÄ²»°²È«Ê¹Ó㬹¥»÷ÕßÄܹ»Í¨¹ýÌáÒé¶ñÒâÒªÇ󣬻ú¹Ø¶ñÒâLogÎļþ´¥·¢Phar·´ÐòÁл¯£¬×îÖÕÔì³ÉÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Seowon-Intech-SWC-9100-Routers_Ô¶³ÌºÅÁîÖ´ÐÐ[CVE-2013-7179][CNNVD-201402-022]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

SeowonIntechSWC-9100RoutersÊǺ«¹úÈðÔªÒóÌØ£¨SeowonIntech£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£SeowonIntechSWC-9100·ÓÉÆ÷ÖеÄcgi-bin/diagnostic.cgiÎļþÖеÄpingÖ°ÄÜÖдæÔÚÊäÈëÑéÖ¤·ì϶¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú¡®ping_ipaddr¡¯²ÎÊýÖеÄshellÔª×Ö·ûÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220805

 

ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CoinMiner_ÃÅÂÞ±ÒJSON-RPCºÍ̸_ÍÚ¿ó½ÚÔìºÅÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý2(XMR)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö£º

¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCºÍ̸ÒÉËÆÅ²ÓÃÁËÃÅÂÞ±ÒÍÚ¿óAPIº¯Êý¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿ç˵»°Ô¶³ÌŲÓúÍ̸¡£ÓÐÎı¾´«ÊäÊý¾ÝÓ×£¬±ãÓÚµ÷ÊÔÀ©´óµÄÌØµã¡£Ëü¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏàÓ¦µÄ´¦Öù涨,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÌåʽ£¬¹æ·¶×ÔÉíÊÇ´«ÊäÎ޹صÄ£¬Äܹ»ÓÃÓÚ¹ý³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»ò¸÷ÀàÐÂÎÅͨѶ»·¾³¡£ÃÅÂÞ±ÒÀûÓÿª·¢½Ó¿ÚѡȡJSON-PRC³ß¶È£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹صÄ£¬Äܹ»Ê¹ÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëÍÚ¿ó½Úµã½»»¥¡£ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£Õ¼ÓÃÓû§×ÊÔ´½øÐÐÍÚ¿ó¡£

¸üй¦·ò£º

20220805


 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌºÅÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÓ×®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâOGNL±í°×ʽ¡£·ì϶´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷³É¹¦£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220805