ÿÖÜÉý¼¶Í¨¸æ-2022-01-04
Ðû²¼Ê±¼ä 2022-01-04ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ntopng_ȨÏÞÈÆ¹ýÎó²î[¹¥»÷ʵÑé][CVE-2021-28073] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ntopngÊÇÒ»¿î»ùÓÚWebµÄÁ÷Á¿ÆÊÎöÓ뼯Á÷¹¤¾ß¡£¡£¡£ntopng±£´æÈ¨ÏÞÈÆ¹ýÎó²î£¬£¬£¬£¬£¬ÆäCVEºÅΪCVE-2021-28073¡£¡£¡£¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬£¬£¬ÈƹýÏà¹ØÈÏÖ¤£¬£¬£¬£¬£¬ÅäºÏÏà¹Ø¹¦Ð§Ôì³Éí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_PbootCMS_v2.0.7_ǰ̨Îļþ°üÀ¨Îó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | PbootCMSÊÇÒ»¿î¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾¿ª·¢½¨ÉèÖÎÀíϵͳ¡£¡£¡£pbootcms2.07°æ±¾ÖÐǰ̨¿ØÖÆÆ÷TagControllerÖеÄindexÒªÁì±£´æÎļþ°üÀ¨Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»ñȡĿµÄÖ÷»úȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_PbootCMS_v2.0.7_í§ÒâÎļþ¶ÁÈ¡ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | PbootCMSÊÇÒ»¿î¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾¿ª·¢½¨ÉèÖÎÀíϵͳ¡£¡£¡£pbootcms2.07°æ±¾ÖÐǰ̨list²ÎÊý±£´æí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î»ñȡĿµÄÖ÷»úȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_DedeCMSV6.0.3_catalog_edit.php_Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢£¬£¬£¬£¬£¬¾ßÓкÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬£¬£¬£¬£¬²¢ÇÒÍêÈ«¿ª·ÅÔ´´úÂë¡£¡£¡£ØÊºǫ́catalog_edit.phpÎļþ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÄõ½Ä¿µÄÖ÷»úȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_DedeCMSV6.0.3_freelist_edit.php_Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢£¬£¬£¬£¬£¬¾ßÓкÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬£¬£¬£¬£¬²¢ÇÒÍêÈ«¿ª·ÅÔ´´úÂë¡£¡£¡£ØÊºǫ́freelist_edit.phpÎļþ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÄõ½Ä¿µÄÖ÷»úȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | TCP_Éó¼ÆÊÂÎñ_JAVA_LDAPÇëÇóŲÓà |
Çå¾²ÀàÐÍ£º | Çå¾²Éó¼Æ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐLDAPÇëÇ󡣡£¡£LDAPÊÇÒ»¸öÇáÁ¿¼¶Ä¿Â¼»á¼ûÐÒé¡£¡£¡£ÈôÔ´IPÖ÷»ú±£´æJAVA·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃJNDIÀ´Å²ÓÃLDAP£¬£¬£¬£¬£¬¿ÉÄܱ£´æÔ¶³Ì»á¼û¶ñÒ⹤¾ßµÄΣº¦¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | TCP_Éó¼ÆÊÂÎñ_JAVA_RMIÇëÇóŲÓà |
Çå¾²ÀàÐÍ£º | Çå¾²Éó¼Æ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐRMIÇëÇ󡣡£¡£RMI¼´Ô¶³ÌÒªÁìŲÓÃ(RemoteMethodInvocation)£¬£¬£¬£¬£¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³ÌÀú³ÌŲÓõÄJavaAPI¡£¡£¡£ÈôÔ´IPÖ÷»ú±£´æJAVA·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃJNDIÀ´Å²ÓÃRMI£¬£¬£¬£¬£¬¿ÉÄܱ£´æÔ¶³Ì»á¼û¶ñÒ⹤¾ßµÄΣº¦¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Ô¶³Ì»á¼ûJava_classÎļþ |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò: | ´ËÊÂÎñ¼ì²âJAVAÔ¶³Ì»á¼ûclassÎļþµÄÐÐΪ¡£¡£¡£ÔÚjavaÎó²îÖУ¬£¬£¬£¬£¬±£´æ´ó×Ú·´ÐòÁл¯ºÍÏÂÁîÖ´ÐÐÎó²î»áʹÓõ½Ô¶³ÌŲÓÃÐÒéÈ¥»á¼û¶ñÒâÀàµÄÊÖ·¨£¬£¬£¬£¬£¬À´ÊµÏÖí§ÒâÏÂÁîÖ´ÐУ¬£¬£¬£¬£¬Î£º¦½Ï´ó¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_JAVA_ŲÓÃRMIÔ¶³ÌÏÂÔØclass |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ´ËÊÂÎñ¼ì²âJAVAŲÓÃRMIÔ¶³ÌÏÂÔØclassµÄÐÐΪ¡£¡£¡£RMI¼´Ô¶³ÌÒªÁìŲÓ㬣¬£¬£¬£¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³ÌÀú³ÌŲÓõÄjavaAPI.ÔÚjavaÎó²îÖУ¬£¬£¬£¬£¬±£´æ´ó×Ú·´ÐòÁл¯ºÍÏÂÁîÖ´ÐÐÎó²î»áʹÓõ½RMIÔ¶³Ì»á¼û¶ñÒâÀàµÄÊÖ·¨£¬£¬£¬£¬£¬À´ÊµÏÖí§ÒâÏÂÁîÖ´ÐУ¬£¬£¬£¬£¬Î£º¦½Ï´ó¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_Pupy_ÅþÁ¬C2ЧÀÍÆ÷ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | ¼ì²âµ½Óɺڿ͹¤¾ßPupyÌìÉúµÄhttpÔ¶¿ØºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£¡£¡£Ö´Ðк󣬣¬£¬£¬£¬¹¥»÷Õß¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе£¬£¬£¬£¬£¬²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¶à¹¦Ð§Ô¶¿ØºóÃźͺóÉøÍ¸¹¤¾ß¡£¡£¡£Ëü¾ßÓÐall-in-memoryÖ´Ðй¦Ð§£¬£¬£¬£¬£¬Õ¼ÓÿռäºÜÊÇС¡£¡£¡£Pupy¿ÉÒÔʹÓöàÖÖ·½·¨¾ÙÐÐͨѶ£¬£¬£¬£¬£¬Ê¹Ó÷´Éä×¢ÈëǨáãµ½Àú³ÌÖУ¬£¬£¬£¬£¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢python°üºÍpythonC-extensions¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | UDP_ľÂíºóÃÅ_Pupy_ÅþÁ¬C2ЧÀÍÆ÷ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | ¼ì²âµ½Óɺڿ͹¤¾ßPupyÌìÉúµÄhttpÔ¶¿ØºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£¡£¡£Ö´Ðк󣬣¬£¬£¬£¬¹¥»÷Õß¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе£¬£¬£¬£¬£¬²¢¾ÙÐкáÏòÒÆ¶¯¡£¡£¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¶à¹¦Ð§Ô¶¿ØºóÃźͺóÉøÍ¸¹¤¾ß¡£¡£¡£Ëü¾ßÓÐall-in-memoryÖ´Ðй¦Ð§£¬£¬£¬£¬£¬Õ¼ÓÿռäºÜÊÇС¡£¡£¡£Pupy¿ÉÒÔʹÓöàÖÖ·½·¨¾ÙÐÐͨѶ£¬£¬£¬£¬£¬Ê¹Ó÷´Éä×¢ÈëǨáãµ½Àú³ÌÖУ¬£¬£¬£¬£¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢python°üºÍpythonC-extensions¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ£¬£¬£¬£¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬£¬£¬£¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬£¬£¬£¬£¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£¡£¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿£¬£¬£¬£¬£¬ÒÔÊÇÐèÒªÖØµã¹Ø×¢¡£¡£¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |
ÊÂÎñÃû³Æ£º | HTTP_ÅÀ³æBot»á¼û |
Çå¾²ÀàÐÍ£º | Çå¾²Éó¼Æ |
ÊÂÎñÐÎò: | ¼ì²âµ½ÅÀ³æBot¶ÔÄ¿µÄIPÖ÷»úµÄweb»á¼û,¿ÉÄÜÔÚ¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐÒ³ÃæÅÀÈ¡¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220104 |


¾©¹«Íø°²±¸11010802024551ºÅ