ÿÖÜÉý¼¶Í¨¸æ-2023-01-10

Ðû²¼Ê±¼ä 2023-01-10
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Lucee_Admin_imgProcess.cfm_í§ÒâÎļþдÈë[CVE-2021-21307]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃLuceeAdminÖеÄí§ÒâÎļþдÈëÎó²î¡£¡£ ¡£¡£¡£LuceeServerÊÇÒ»ÖÖ¶¯Ì¬µÄ¡¢»ùÓÚJava(JSR-223)µÄ±ê¼ÇºÍ¾ç±¾ÓïÑÔ £¬£¬£¬£¬£¬£¬ÓÃÓÚ¿ìËÙWebÓ¦ÓóÌÐò¿ª·¢¡£¡£ ¡£¡£¡£ÔÚ°æ±¾5.3.7.47¡¢5.3.6.68»ò5.3.5.96֮ǰµÄLuceeAdminÖб£´æÎ´¾­Éí·ÝÑéÖ¤µÄí§ÒâÎļþдÈëÎó²î¡£¡£ ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230110

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WeiPHP_5.0_Îļþ¶ÁÈ¡[CNVD-2020-68596]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»ú £¬£¬£¬£¬£¬£¬ÕýÔÚʹÓÃWeiphp5.0ǰ̨Îļþí§Òâ¶ÁÈ¡Îó²î¾ÙÐй¥»÷ £¬£¬£¬£¬£¬£¬¶ÁÈ¡Êý¾Ý¿âÉèÖõÈÃô¸ÐÎļþ¡£¡£ ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230110

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Struts2_S2-001/S2-002_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Struts2ÊÇÒ»¸ö»ùÓÚMVCÉè¼ÆÄ£Ê½µÄWebÓ¦Óÿò¼Ü £¬£¬£¬£¬£¬£¬¸ÃÎó²îÓÉÓÚÓû§Ìá½»±íµ¥Êý¾Ý²¢ÇÒÑé֤ʧ°Üʱ £¬£¬£¬£¬£¬£¬ºó¶Ë»á½«Óû§Ö®Ìõ¼þ½»µÄ²ÎÊýֵʹÓÃOGNL±í´ïʽ%{value}¾ÙÐÐÆÊÎö £¬£¬£¬£¬£¬£¬È»ºóÖØÐÂÌî³äµ½¶ÔÓ¦µÄ±íµ¥Êý¾ÝÖС£¡£ ¡£¡£¡£ÀýÈç×¢²á»òµÇÂ¼Ò³Ãæ £¬£¬£¬£¬£¬£¬Ìύʧ°Üºó¶ËÒ»Ñùƽ³£»áĬÈÏ·µ»ØÖ®Ìõ¼þ½»µÄÊý¾Ý £¬£¬£¬£¬£¬£¬ÓÉÓÚºó¶ËʹÓÃ%{value}¶ÔÌá½»µÄÊý¾ÝÖ´ÐÐÁËÒ»´ÎOGNL±í´ïʽÆÊÎö £¬£¬£¬£¬£¬£¬ÒÔÊÇ¿ÉÒÔÖ±½Ó½á¹¹Payload¾ÙÐÐÏÂÁîÖ´ÐС£¡£ ¡£¡£¡£

¸üÐÂʱ¼ä£º

20230110