ÿÖÜÉý¼¶Í¨¸æ-2022-10-18

Ðû²¼Ê±¼ä 2022-10-18
ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_webuploader_0.1.15_ÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃwebuploader0.1.15°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î¾ÙÐй¥»÷£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ ¡£¡£¡£¡£WebUploaderÊÇÓÉBaiduWebFE(FEX)ÍŶӿª·¢µÄÒ»¸ö¼òÆÓµÄÒÔHTML5ΪÖ÷£¬£¬ £¬£¬£¬£¬FLASHΪ¸¨µÄÏÖ´úÎļþÉÏ´«×é¼þ ¡£¡£¡£¡£ÔÚÏÖ´úµÄä¯ÀÀÆ÷ÄÚÀïÄܳä·ÖÑéÕ¹HTML5µÄÓÅÊÆ£¬£¬ £¬£¬£¬£¬Í¬Ê±ÓÖ²»ÞðÆúÖ÷Á÷IEä¯ÀÀÆ÷£¬£¬ £¬£¬£¬£¬ÑØÓÃÔ­À´µÄFLASHÔËÐÐʱ£¬£¬ £¬£¬£¬£¬¼æÈÝIE6+£¬£¬ £¬£¬£¬£¬iOS6+,android4+ ¡£¡£¡£¡£Á½Ì×ÔËÐÐʱ£¬£¬ £¬£¬£¬£¬Í¬ÑùµÄŲÓ÷½·¨£¬£¬ £¬£¬£¬£¬¿É¹©Óû§í§ÒâÑ¡Óà ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2963]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PHP-zerodiumºóÃÅ_í§Òâ´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄÆÊÎöÀú³ÌÖз¢Ã÷£¬£¬ £¬£¬£¬£¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»Ð®ÖÆµÄÍøÕ¾ÉÏ£¬£¬ £¬£¬£¬£¬²¢ÇÒ½ÓÄÉÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷£¬£¬ £¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢Ö°Ô±µÄÃûÒåÀ´Ìá½»´ËCOMMIT ¡£¡£¡£¡£ÏÖÔÚΪֹPHP¹Ù·½²¢Î´¾Í¸ÃÊÂÎñ¾ÙÐиü¶àÅû¶£¬£¬ £¬£¬£¬£¬ÌåÏÖ´Ë´ÎЧÀÍÆ÷±»ºÚµÄÏêϸϸ½ÚÈÔÔÚÊӲ쵱ÖÐ ¡£¡£¡£¡£ÓÉÓÚ´ËÊÂÎñµÄÓ°Ï죬£¬ £¬£¬£¬£¬PHPµÄ¹Ù·½´úÂë¿âÒѾ­±»Î¬»¤Ö°Ô±Ç¨áãÖÁGitHubƽ̨£¬£¬ £¬£¬£¬£¬Ö®ºóµÄÏà¹Ø´úÂë¸üС¢Ð޸Ľ«»á¶¼ÔÚGitHubÉϾÙÐÐ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_WebLogic_·´ÐòÁл¯_XXE×¢Èë[CVE-2020-2949]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃweblogic3.7.1.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾±£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬Í¨¹ýt3ЭÒéת´ï¶ñÒâµÄÐòÁл¯Êý¾Ý´Ó¶ø´¥·¢XXEÎó²î£¬£¬ £¬£¬£¬£¬¶ÁȡĿµÄϵͳÃô¸ÐÎļþ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14825]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃ10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0ºÍ14.1.1.0.0°æ±¾µÄweblogicÖб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_apache_solr_XXE×¢Èë[CVE-2018-1308][CNNVD-201804-415]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPʹÓÃApachesolr1.2-6.6.2ºÍ7.0.0-7.2.1°æ±¾Öб£´æµÄXXEÎó²î¾ÙÐÐÎļþ¶ÁÈ¡²Ù×÷£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄÃô¸ÐÐÅÏ¢ ¡£¡£¡£¡£ApacheSolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷ЧÀÍ£¬£¬ £¬£¬£¬£¬Ê¹ÓÃJavaÓïÑÔ¿ª·¢£¬£¬ £¬£¬£¬£¬Ö÷Òª»ùÓÚHTTPºÍApacheLuceneʵÏÖµÄ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-24616][CNNVD-202008-1195]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLJacksonµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²îÏòÄ¿µÄip¾ÙÐз´ÐòÁл¯¹¥»÷ ¡£¡£¡£¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß ¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ×é¼þ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Jackson_Databind_dbcp2_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36180/CVE-2020-36182/CVE-2020-36184/CVE-2020-36185][CNNVD-202101-326/CNNVD-202101-325/CNNVD-202101-344/CNNVD-202101-337]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFasterXMLjackson-databind<2.9.9.2ºÍ>=2.0.0,<=2.9.10.7°æ±¾Öб£´æµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ ¡£¡£¡£¡£JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´®£¬£¬ £¬£¬£¬£¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_IBM_WebSphere_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-4279]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼʹÓÃIBM_WebSphereV9.0.0.0-V9.0.0.11£¬£¬ £¬£¬£¬£¬V8.5.0.0-V8.5.5.15£¬£¬ £¬£¬£¬£¬v7.0Öб£´æµÄ´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2555]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPʹÓÃweblogic·´ÐòÁл¯Îó²î¾ÙÐй¥»÷µÄÐÐΪ£¬£¬ £¬£¬£¬£¬OracleCoherenceΪOracleÈÚºÏÖÐÐļþÖеIJúÆ·£¬£¬ £¬£¬£¬£¬ÔÚWebLogic12c¼°ÒÔÉϰ汾ÖÐĬÈϼ¯³Éµ½WebLogic×°ÖðüÖУ¬£¬ £¬£¬£¬£¬¹¥»÷Õßͨ¹ýt3ЭÒé·¢ËͽṹµÄÐòÁл¯Êý¾Ý£¬£¬ £¬£¬£¬£¬ÄܹýÔì³ÉÏÂÁîÖ´ÐеÄЧ¹û

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Atlassian_Confluence_Îļþ¶ÁÈ¡

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃAtlassianConfluence5.8.17֮ǰ°æ±¾Öб£´æµÄÎļþ¶ÁÈ¡Îó²î¾ÙÐй¥»÷µÄÐÐΪ£¬£¬ £¬£¬£¬£¬´Ó¶ø¶ÁȡĿµÄϵͳµÄÃô¸ÐÎļþ ¡£¡£¡£¡£AtlassianonfluenceÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×רҵµÄÆóҵ֪ʶÖÎÀíÓëЭͬÈí¼þ£¬£¬ £¬£¬£¬£¬Ò²¿ÉÒÔÓÃÓÚ¹¹½¨ÆóÒµWiKi ¡£¡£¡£¡£¸ÃÈí¼þ¿ÉʵÏÖÍŶӳÉÔ±Ö®¼äµÄЭ×÷ºÍ֪ʶ¹²Ïí ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zyxel·À»ðǽ_ÏÂÁîÖ´ÐÐ[CVE-2022-30525][CNNVD-202205-3104]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃZyxel·À»ðǽ5.00-5.21°æ±¾±£´æµÄÏÂÁîÖ´ÐÐÎó²î¾ÙÐй¥»÷£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ ¡£¡£¡£¡£ZyxelUSGFLEXÊÇÖйúZyxel¹«Ë¾µÄÒ»¿î·À»ðǽ£¬£¬ £¬£¬£¬£¬¿ÉÒÔÌṩÎÞаµÄVPNÑ¡Ï£¬ £¬£¬£¬£¬ÎªÔ¶³ÌÊÂÇéºÍÖÎÀíÌṩÎÞаµÄÇå¾²Ô¶³Ì»á¼û ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JBoss_JMXInvokerServlet·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-7501]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃJBoss6.4.0֮ǰ°æ±¾ÖÐÔÚ/invoker/JMXInvokerServletµÄ·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýApacheCommonsCollectionsÖеÄGadgetʵÏÖí§Òâ´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷ ¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader ¡£¡£¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬£¬ £¬£¬£¬£¬ÔËÐк󣬣¬ £¬£¬£¬£¬¿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬ £¬£¬£¬£¬ÈçºóÃÅµÈ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Weblogic_Server_´úÂëÖ´ÐÐ[CVE-2021-2109][CNNVD-202101-1453]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogic10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0°æ±¾±£´æµÄ´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳȨÏÞ ¡£¡£¡£¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver£¬£¬ £¬£¬£¬£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖÐÐļþ£¬£¬ £¬£¬£¬£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀí´óÐÍÂþÑÜʽWebÓ¦Óá¢ÍøÂçÓ¦ÓúÍÊý¾Ý¿âÓ¦ÓõÄJavaÓ¦ÓÃЧÀÍÆ÷ ¡£¡£¡£¡£½«JavaµÄ¶¯Ì¬¹¦Ð§ºÍJavaEnterprise±ê×¼µÄÇå¾²ÐÔÒýÈë´óÐÍÍøÂçÓ¦ÓõĿª·¢¡¢¼¯³É¡¢°²ÅźÍÖÎÀíÖ®ÖÐ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221018