ÿÖÜÉý¼¶²¼¸æ-2023-01-03
°ä²¼¹¦·ò 2023-01-03
ÊÂÎñÃû³Æ£º | TCP_ľÂíºóÃÅ_SparkRat_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½SparkRatÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËSparkRat¡£SparkRatÊÇÒ»¸öGo±àдµÄ£¬ÍøÒ³UI¡¢¿çƽ̨ÒÔ¼°¶àÖ°ÄܵÄÔ¶³Ì½ÚÔìºÍ¼à¿Ø¹¤¾ß£¬Äܹ»ËæÊ±ËæµØ¼à¿ØºÍ½ÚÔìËùÓÐÉ豸¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ejs_Ä£°å×¢Èë_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ö÷»úÔÚÔâ·êejsÄ£°å×¢Èë¹¥»÷£¬Node.jsejsÄ£¿é¿ÉÄÜÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂ룬ÕâÊÇÓÉÉèÖÃ[²é¿´Ñ¡Ïî][Êä³öº¯ÊýÃû³Æ]ÖеķþÎñÆ÷¶ËÄ£°å×¢ÈëȱµãÒýÆðµÄ¡£Í¨¹ý·¢ËÍÌØÔìµÄHTTPÒªÇóÒÔʹÓÃËÁÒâOSºÅÁ¸ÇoutputFunctionNameÑ¡Ï¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚϵͳÉÏÖ´ÐÐËÁÒâ´úÂë¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_Éó¼ÆÊÂÎñ_Nacos_Ãô¸ÐÒ³Ãæ½Ó¼û |
°²È«ÀàÐÍ£º | °²È«Éó¼Æ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½µ±Ç°Ö÷»úÔÚÔâ·ênacosÃô¸ÐÒ³Ãæ½Ó¼û£¬NacosÊÇDynamicNamingandConfigurationServiceµÄÊ××Öĸ¼ò³Æ£¬Ò»¸ö¸üÒ×ÓÚ¹¹½¨ÔÆÔÉúÀûÓõĶ¯Ì¬·þÎñ·¢ÏÖ¡¢ÅäÖÃÖÎÀíºÍ·þÎñÖÎÀíÆ½Ì¨¡£NacosÓÃÓÚ·¢ÏÖ¡¢ÅäÖúÍÖÎÀí΢·þÎñ¡£NacosÌṩÁËÒ»×éµ¥Ò»Ò×ÓõĸöÐÔ¼¯£¬Ô®ÊÖÄú¼±¾çʵÏÖ¶¯Ì¬·þÎñ·¢ÏÖ¡¢·þÎñÅäÖᢷþÎñÔªÊý¾Ý¼°Á÷Á¿ÖÎÀí¡£NacosÔ®ÊÖÄú¸ü»ð¿ìºÍÈÝÒ׵ع¹½¨¡¢½»¸¶ºÍÖÎÀí΢·þÎñƽ̨¡£NacosÊǹ¹½¨ÒÔ¡°·þÎñ¡±ÎªÖÐÐĵÄÏÖ´úÀûÓüܹ¹(ÀýÈç΢·þÎñ·¶Ê½¡¢ÔÆÔÉú·¶Ê½)µÄ·þÎñ»ù´¡ÉèÊ©¡£Nacos¹Ù·½ÔÚgithub°ä²¼µÄissueÖÐÅû¶AlibabaNacos´æÔÚÒ»¸öÓÉÓÚ²»µ±´¦ÖÃUser-Agentµ¼ÖµÄδÊÚȨ½Ó¼û·ì϶¡£Í¨¹ý¸Ã·ì϶£¬¹¥»÷ÕßÄܹ»½øÐÐËÁÒâ²Ù×÷£¬Ô̺¬´´½¨ÐÂÓû§²¢½øÐеǼºó²Ù×÷¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_XStream_DOS[CVE-2022-41966] |
°²È«ÀàÐÍ£º | »Ø¾ø·þÎñ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÉ豸ÔÚÀûÓÃxstreamÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸£»Xstream½â×éʱ´¦ÖõÄÁ÷Ô̺¬ÀàÐÍÐÅÏ¢ÒÔ³Áд´½¨ÒÔǰ±àдµÄ¶ÔÏó¡£XStreamÒò¶ø»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐÂÊ·ý¡£¹¥»÷ÕßÄܹ»°Ñ³Ö´¦ÖùýµÄÊäÈëÁ÷²¢´úÌæ»ò×¢ÈëÄܹ»Ö´ÐÐËÁÒâshellºÅÁîµÄ¶ÔÏó¡£XStreamÖдæÔڻؾø·þÎñ·ì϶(CVE-2022-41966)£¬XStreamÔÚ½«XML·´ÐòÁл¯Îª¶ÔÏóʱ´æÔÚ²Ö¿âÒç³ö£¬Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý°Ñ³ÖÊäÈëÁ÷£¬Ê¹XStreamÔڵݹéÉ¢ÁÐÍÆËãʱ´¥·¢²Ö¿âÒç³ö£¬µ¼Ö»ؾø·þÎñ¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Splunk_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | SplunkEnterpriseÊÇ»úеÊý¾ÝµÄÒýÇæ¡£Ê¹ÓÃSplunk¿ÉÍøÂç¡¢Ë÷ÒýºÍÀûÓÃËùÓÐÀûÓ÷¨Ê½¡¢·þÎñÆ÷ºÍÉ豸ÌìÉúµÄ¼±¾çÒÆ¶¯ÐÍÍÆËã»úÊý¾Ý¡£¹ØÁª²¢·ÖÎöÓâÔ½¶à¸öϵͳµÄ¸´ÔÓÊÂÎñ¡£»ñȡеµ´ÎµÄÔËÓª¿É¼ûÐÔÒÔ¼°ITºÍÒµÎñÖÇÄÜ¡£ÓÉÓÚSplunkEnterpriseÖÐSimpleXMLÒDZí°å´æÔÚ´úÂë×¢È룬¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õ߿ɻú¹ØÌØÔìµÄÊý¾Ý°ü£¬Í¨¹ýPDFµ¼³ö²Ù×÷´¥·¢ËÁÒâ´úÂëÖ´ÐС£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Webmin_ºÅÁîÖ´ÐÐ[CVE-2019-15107] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_ÌáÈ¡¹¥»÷_Webmin_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2019-15107]¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâºÅÁî¡£WebminÊÇĿǰְÄÜ×î׳´óµÄ»ùÓÚWebµÄUnixϵͳÖÎÀí¹¤¾ß¡£ÖÎÀíԱͨ¹ýä¯ÀÀÆ÷½Ó¼ûWebminµÄ¸÷ÀàÖÎÀíÖ°Äܲ¢ÊµÏÖÏàÓ¦µÄÖÎÀí×÷Ϊ¡£ÔÚWebmin<=1.920µÄ°æ±¾ÖУ¬¸Ã·ì϶ÓÉÓÚpassword_change.cgiÎļþÔÚ³ÁÖÃÃÜÂëÖ°ÄÜÖдæÔÚÒ»¸ö´úÂëÖ´Ðзì϶£¬¸Ã·ì϶ÔÊÐí¶ñÒâµÚÈý·½ÔÚ¶ÌȱÊäÈëÑéÖ¤µÄÇé¿ö϶øÖ´ÐжñÒâ´úÂë¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_IceWarp_WebClient_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | IceWarp,Inc.ÊÇÒ»¼ÒλÓڽݿ˹²ºÍ¹ú²¼À¸ñµÄÈí¼þ¹«Ë¾¡£Ëü¿ª·¢ÁËIceWarpMailServer£¬ÕâÊÇÒ»ÏîÃæÏòÖÐÓ×ÐÍÆóÒµµÄµç×ÓÓʼþ¡¢ÐÂÎźͺÏ×÷·þÎñ¡£ÆäÖиÃϵͳµÄWebClientbasic²¿ÃÅ´æÔÚ·ì϶£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâpayloadÔì³É´úÂëÖ´ÐС£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_YouPHPTube_Encoder_ºÅÁîÖ´ÐÐ[CVE-2019-5127] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | YouPHPTubeEncoderÊÇYouPHPTubeµÄ±àÂëÆ÷²å¼þ£¬¸Ã²å¼þ¿ÉÔÚYouPHPTubeÖÐÌṩ±àÂëÆ÷Ö°ÄÜ¡£Ê¹ÓÃÕßÔÚ×Ô¼ºµÄ·þÎñÆ÷ÉÏ×°Öò¢Ê¹ÓÃYouPHPTubeEncoderÒÔÈ¡´úµÚÈý·½¹«¹²±àÂëÆ÷·þÎñÆ÷£¬Äܹ»¸ü¼±¾ç±ã½ÝµÄ±àÂë×Ô¼ºµÄÊÓÆµ£¬²¢ÇÒ»¹Äܹ»Ê¹ÓÃ˽Óз½Ê½¶Ô×Ô¼ºµÄÊÓÆµ½øÐбàÂë¡£ÔÚYouPHPTubeEncoder2.3ÖУ¬´æÔÚÎÞÐèÉí·ÝÑéÖ¤µÄºÅÁî×¢Èë·ì϶¡£¹¥»÷ÕßÄܹ»·¢ËÍÔ̺¬Ìض¨²ÎÊýµÄWebÒªÇóÀ´´¥·¢ÕâЩ·ì϶¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jinja2_SSTI_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | jinja2Ä£°åÖÐʹÓÃ{{}}Óï·¨°µÊ¾Ò»¸ö±äÁ¿£¬ËüÊÇÒ»ÖÖÌØÊâµÄռλ·û¡£µ±ÀûÓÃjinja2½øÐÐäÖȾµÄʱ³½£¬Ëü»á°ÑÕâÐ©ÌØÊâµÄռλ·û½øÐÐÌî³ä/´úÌæ£¬jinja2Ö§³ÖpythonÖÐËùÓеÄPythonÊý¾ÝÀàÐͺñÈÁÐ±í¡¢×ֶΡ¢¶ÔÏóµÈ¡£Jinja2äÖȾʱ²»½ö½öÖ»½øÐÐÌî³äºÍ´úÌæ£¬»¹¿ÉÄÜÖ´Ðв¿Ãűí°×ʽ¡£Èô¹¥»÷ÕßÄܳɹ¦½ÚÔì´«ÈëµÄ±í°×ʽ£¬ÔòÄܹ»Í¨¹ý·þÎñ¶ËÄ£°æäÖȾÔÚÖ¸±êÖ÷»úÉÏÖ´ÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20230103 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2021-2135][CNNVD-201804-803] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracleWebLogic·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÀûÓ÷¨Ê½·þÎñÆ÷£¬ÊÇÒ»¸ö»ùÓÚJavaEE¼Ü¹¹µÄWebÖÐÑë¼þ¡£WebLogic´æÔÚJava·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐиßΣ°²È«·ì϶¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ñÒâ´úÂ룬µ±WebLogicÖ´ÐÐJava·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÓÉÓÚWebLogic½¨¸´·ì϶ѡȡÁ˺ÚÃûµ¥¹ýÂË»úÔ죬ÓÐʱ³½¿ÉÄܵ¼Ö·ì϶½¨¸´²»³¹µ×еķ´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶Ƶ·¢£¬Òò¶øÇëÇ×êǹØ×¢Oracle¹Ù·½°ä²¼µÄ·ì϶²¹¶¡£¬ÊµÊ±½øÐв¹¶¡¸üÐÂÒÔÈ·±£·þÎñÆ÷°²È«¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Atlassian_Crowd_ÎļþÉÏ´«[CNNVD-201905-1031] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÔÚÀûÓÃAtlassianCrowdÔÚuploadplugin.action´¦µÄÎļþÉÏ´«·ì϶½øÐй¥»÷£¬ÉÏ´«¶ñÒâjar²å¼þ£¬´Ó¶øÊ¹µÃAtlassianCrowdÖ±½Ó×°Öøòå¼þ´Ó¶øÖ´ÐÐËÁÒâºÅÁî¡£AtlassianCrowdÊÇÒ»Ì×»ùÓÚWebµÄµ¥µãµÇ¼ϵͳ¡£¸ÃϵͳΪ¶àÓû§¡¢ÍøÂçÀûÓ÷¨Ê½ºÍĿ¼·þÎñÆ÷ÌṩÑéÖ¤¡¢ÊÚȨµÈÖ°ÄÜ¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_XStream_·´ÐòÁл¯[CVE-2013-7285] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | XStreamʵÏÖÁËÒ»Ì×ÐòÁл¯ºÍ·´ÐòÁл¯»úÔ죬Ö÷ÌâÊÇͨ¹ýConverterת»»Æ÷À´½«XMLºÍ¶ÔÏóÖ®¼ä½øÐÐÏ໥µÄת»»£¬XStream·´ÐòÁл¯·ì϶µÄ´æÔÚÊÇÓÉÓÚXStreamÖ§³ÖÒ»¸öÃûΪDynamicProxyConverterµÄת»»Æ÷£¬¸Ãת»»Æ÷Äܹ»½«XMLÖÐdynamic-proxy±êÇ©ÄÚÈÝת»»³É¶¯Ì¬´úÀíÀà¶ÔÏ󣬶øµ±·¨Ê½Å²ÓÃÁËdynamic-proxy±êÇ©ÄÚµÄinterface±êǩָÏòµÄ½Ó¿ÚÀàÉêÃ÷µÄ²½Öèʱ£¬¾Í»áͨ¹ý¶¯Ì¬´úÀí»úÔì´úÀí½Ó¼ûdynamic-proxy±êÇ©ÄÚhandler±êǩָ¶¨µÄÀಽÖ裻ÀûÓÃÕâ¸ö»úÔ죬¹¥»÷ÕßÄܹ»»ú¹Ø¶ñÒâµÄXMLÄÚÈÝ£¬µ±¹¥»÷Õß´Ó±í²¿ÊäÈë¸Ã¶ñÒâXMLÄÚÈݺ󼴿ɴ¥·¢·´ÐòÁл¯·ì϶¡¢´ïµ½ËÁÒâ´úÂëÖ´ÐеÄÖ÷ÕÅ¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨºÅÁî×¢Èë |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬exportovpn½Ó¿Ú´æÔÚºÅÁî×¢È룬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâºÅÁî¡£ |
¸üй¦·ò£º | 20230103 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_ÈôÒÀCMS_Ô¶³ÌºÅÁîÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ÈôÒÀºó¶ÜÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄÌåʽ£¬¿ÉÓÃÓÚJava¶ÔÏóµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºó¶Ü´òË㹤×÷´¦£¬¶ÔÓÚ´«ÈëµÄ"ŲÓÃÖ¸±ê×Ö·û´®"ûÓÐÈκÎУÑ飬µ¼Ö¹¥»÷ÕßÄܹ»»ú¹ØpayloadÔ¶³ÌŲÓÃjar°ü£¬´Ó¶øÖ´ÐÐËÁÒâºÅÁî¡£ |
¸üй¦·ò£º | 20230103 |


¾©¹«Íø°²±¸11010802024551ºÅ