ÿÖÜÉý¼¶²¼¸æ-2022-11-15

°ä²¼¹¦·ò 2022-11-15
ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_D-LinkDCS-2530LºÍDCS-2670L_¼à¿ØÃô¸ÐÐÅϢй¶[CVE-2020-25078][CNNVD-202009-083]

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÔÚͨ¹ý½Ó¼ûD-LinkDCS-2530LºÍDCS-2670LµÄ"/config/getuser"»ñÈ¡ÖÎÀíÔ±ÐÅÏ¢¼°ÃÜÂë¡£D-LinkDCS-2530LºÍDCS-2670L¾ùÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÎÞÏßÍøÂçÐźÅÀ©´óÆ÷¡£D-LinkDCS-2530L1.06.01Hotfix֮ǰ°æ±¾ºÍDCS-2670L2.02¼°Ö®Ç°°æ±¾´æÔÚÐÅϢй¶·ì϶¡£

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËû¿ÉÒÉÐÐΪ_SnakeYAML·´ÐòÁл¯_×Ô½ç˵TAG²ð·ÖÀàÃû

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÏòÖ¸±êÖ÷»ú·¢ËÍÔ̺¬Í¨¹ý×Ô½ç˵TAG £¬²ð·ÖjavaÀàÃûµÄSnakeYAMLÐòÁл¯Êý¾Ý £¬´Ó¶øÈƹý¼ì²âÉ豸¶ÔSnakeYAML·´ÐòÁл¯ÀûÓÃÁ´µÄ¼ì²â¡£SnakeYamlÊÇJavaÓÃÓÚ½âÎöYaml£¨YetAnotherMarkupLanguage£©ÌåʽÊý¾ÝµÄÀà¿â £¬ÆäÖÐÄܹ»Í¨¹ý×Ô½ç˵tag´¦ÖÃÆ÷²ð·ÖjavaÀàÃû

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

TCP_ÆäËû¿ÉÒÉÐÐΪ_java·´ÐòÁл¯_TC_RESETÔàÊý¾Ý

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÏòÖ¸±êÖ÷»ú·¢ËÍÔ̺¬´óÁ¿TC_RESETÔàÊý¾ÝµÄÐòÁл¯Êý¾Ý £¬´Ó¶øÈƹý¼ì²âÉ豸¶Ôjava·´ÐòÁл¯ÀûÓÃÁ´µÄ¼ì²â¡£TC_RESETÊÇjavaÐòÁл¯ÌåʽÖÐÓÃÓÚ³ÁÖÃReferenceIDµÄ±êʶ·û £¬Äܹ»Í¨¹ý¸Ã±êʶ·û»ú¹ØÔ̺¬Éó²ìÔàÊý¾ÝµÄjavaÐòÁл¯Á÷Á¿¡£

¸üй¦·ò£º

20221115


Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_AxHostState-BinaryFormatterÀûÓÃÁ´_ysoserial¹¤¾ßÀûÓÃ_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢ÏÖµÄʵÓ÷¨Ê½ºÍÃæÏòÊôÐԵıà³Ì¡°Ó×¹¤¾ßÁ´¡±µÄ¼¯ÖÐ £¬Äܹ»ÔÚÊʵ±µÄǰÌáÏÂÀûÓÃ.NETÀûÓ÷¨Ê½Ö´Ðв»°²È«µÄ¶ÔÏó·´ÐòÁл¯¡£Ö÷Çý¶¯·¨Ê½½ÓÊÜÓû§Ö¸¶¨µÄºÅÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄÓ×¹¤¾ßÁ´ÖÐ £¬¶øºó½«ÕâЩ¶ÔÏóÐòÁл¯µ½³ß¶ÈÊä³ö¡£µ±Ààõè¾¶ÉÏÓµÓÐËùÐèÓ×¹¤¾ßµÄÀûÓ÷¨Ê½²»°²È«µØ·´ÐòÁл¯´ËÊý¾Ýʱ £¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖºÅÁîÔÚÀûÓ÷¨Ê½Ö÷»úÉÏÖ´ÐС£

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix_Ó×ÓÚ4.4_δÊÚȨ½Ó¼û

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃZabbixÓ×ÓÚ4.4°æ±¾ÖдæÔÚµÄΪδÊÚȨ½Ó¼û·ì϶ £¬´Ó¶øÔÚδ¾­ÊÚȨµÄÇé¿öϽӼûZabbix·þÎñÆ÷ÉϵÄÊý¾Ý £¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«Éó¼Æ_ÉÏ´«war°ü

°²È«ÀàÐÍ£º

°²È«Éó¼Æ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÏòÖ÷ÕÅIPÖ÷»úÉÏ´«war°ü¡£war°üÊÇJavaWeb·¨Ê½´òµÄ°ü £¬Ò»¸öwar°üÄܹ»Àí½âΪÊÇÒ»¸öwebÏîÄ¿ £¬ÀïÃæÊÇÏîÖ÷ÕÅËùÓÐÆ÷²Ä¡£ÒÔTomcatΪÀý £¬½«War°ü¸éÖÃÔÚÆä\webapps\Ŀ¼Ï £¬¶øºóÆô¶¯Tomcat £¬Õâ¸ö°ü¾Í»á×Ô¶¯½âѹ £¬²¿Êð¡¢°ä²¼µ½web·þÎñÖС£

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Oracle_Weblogic_console_ȨÏÞÈÆ¹ý[CVE-2020-14883][CNNVD-202010-997]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracleWebLogic10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0ºÍ14.1.1.0.0°æ±¾ÖдæÔÚµÄconsoleȨÏÞÈÆ¹ý·ì϶ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»·ÇÊÚȨ½Ó¼ûweblogicconsole £¬Ö®ºóÄܹ»Ê¹ÓÃCVE-2020-14882½ÚÔìÖ¸±êϵͳȨÏÞ¡£¡£WeblogicÊÇĿǰȫÇòÊг¡ÉÏÀûÓÃ×î¿í·ºµÄJ2EE¹¤¾ßÖ®Ò» £¬±»³ÆÎªÒµ½ç×î¼ÑµÄÀûÓ÷¨Ê½·þÎñÆ÷ £¬ÆäÓÃÓÚ¹¹½¨J2EEÀûÓ÷¨Ê½ £¬Ö§³ÖÐÂÖ°ÄÜ £¬¿É½µµÍÔËÓª³É±¾ £¬Ìá¸ß»úÄÜ £¬¼ÓÇ¿¿ÉÀ©´óÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Weblogic_Îļþ¶ÁÈ¡[CVE-2019-2615]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃWeblogic10.3.6.0.0,12.1.3.0.0ºÍ12.2.1.3.0°æ±¾ÖдæÔÚµÄËÁÒâÎļþ¶ÁÈ¡·ì϶ £¬´Ó¶ø»ñȡָ±êÖ÷»úÁé¸ÐÎļþÄÚÈÝ¡£WeblogicÊÇĿǰȫÇòÊг¡ÉÏÀûÓÃ×î¿í·ºµÄJ2EE¹¤¾ßÖ®Ò» £¬±»³ÆÎªÒµ½ç×î¼ÑµÄÀûÓ÷¨Ê½·þÎñÆ÷ £¬ÆäÓÃÓÚ¹¹½¨J2EEÀûÓ÷¨Ê½ £¬Ö§³ÖÐÂÖ°ÄÜ £¬¿É½µµÍÔËÓª³É±¾ £¬Ìá¸ß»úÄÜ £¬¼ÓÇ¿¿ÉÀ©´óÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_Ó×ÓÚ1.5.3_ȨÏÞÈÆ¹ý[CVE-2020-1957][CNNVD-202003-1579]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃApacheShiroÓ×ÓÚ1.5.3ÖÐȨÏÞÈÆ¹ý·ì϶¡£¹¥»÷ÕßÄܹ»¾«ÐÄ»ú¹Ø¶ñÒâµÄURL £¬ÀûÓÃApacheShiroºÍSpringBoot¶ÔURLµÄ´¦ÖõIJî¾à»¯ £¬Äܹ»ÈƹýApacheShiro¶ÔSpringBootÖеÄServletµÄȨÏÞ½ÚÔì £¬ÊµÏÖδÊÚȨ½Ó¼û¡£

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨºÅÁî×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖÐ £¬exportovpn½Ó¿Ú´æÔÚºÅÁî×¢Èë £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâºÅÁî¡£

¸üй¦·ò£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ÈôÒÀCMS_Ô¶³ÌºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ÈôÒÀºó¶ÜÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü £¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄÌåʽ £¬¿ÉÓÃÓÚJava¶ÔÏóµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºó¶Ü´òË㹤×÷´¦ £¬¶ÔÓÚ´«ÈëµÄ"ŲÓÃÖ¸±ê×Ö·û´®"ûÓÐÈκÎУÑé £¬µ¼Ö¹¥»÷ÕßÄܹ»»ú¹ØpayloadÔ¶³ÌŲÓÃjar°ü £¬´Ó¶øÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20221115