ÿÖÜÉý¼¶Í¨¸æ-2022-09-13

Ðû²¼Ê±¼ä 2022-09-13
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ManageEngine_·ÇÊÚȨ»á¼û[CVE-2022-36923][CNNVD-202208-2747]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZohoManageEngineÊÇÒ»Ì×ϵͳÖÎÀíÈí¼þ¡£¡£¡£¡£¡£¡£¡£ÔÚCVE-2022-36923ÖУ¬£¬ £¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬ £¬£¬£¬»ñÈ¡µ½Ïà¹ØAPIKEY£¬£¬ £¬£¬£¬´Ó¶ø¿ÉʹÓûñÈ¡µ½µÄkey¾ÙÐÐÏà¹ØapiŲÓ㬣¬ £¬£¬£¬Ôì³ÉÃô¸ÐÐÅÏ¢×ß©µÈ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÆëÖα¤ÀÝ»ú_·ÇÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Õã½­ÆëÖοƼ¼¹É·ÝÓÐÏÞ¹«Ë¾ÊÇÒ»¼ÒÖ÷Ҫı»®ÅÌËã»úÈíÓ²¼þ¡¢ÍøÂç²úÆ·µÄÊÖÒÕ¿ª·¢µÈÏîÄ¿µÄ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£ÆëÖÎÔËά±¤ÀÝ»úЧÀͶ˱£´æí§ÒâÓû§µÇ¼ϵͳÎó²î£¬£¬ £¬£¬£¬»á¼ûÌØ¶¨µÄUrl¼´¿É»ñµÃºǫ́ȨÏÞ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PHPCMS_V9_register_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃPHPCMSv9registerí§ÒâÎļþÉÏ´«GetshellÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Àֳɺó¿ÉÒÔ»ñµÃÄ¿µÄÖ÷»úµÄWebshell£¬£¬ £¬£¬£¬½øÒ»²½»ñµÃÍøÕ¾µÄ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£¡£PHPCMSÊÇ¿ªÔ´µÄÕûվϵͳ¡£¡£¡£¡£¡£¡£¡£PHPCMSv9.6registerº¯Êý±£´æÉè¼ÆÈ±ÏÝ£¬£¬ £¬£¬£¬info[content]²ÎÊý¹ýÂ˲»ÑϿᣬ£¬ £¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸Ã²ÎÊýÔ¶³Ì°üÀ¨ÎļþÖ±½Ó»ñµÃÍøÕ¾µÄWebshell¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì°üÀ¨Îļþ£¬£¬ £¬£¬£¬»ñÈ¡ÍøÕ¾Webshell¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_ShardingSphere_UI_YAML_ÏÂÁîÖ´ÐÐ[CVE-2020-1947]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼʹÓÃApache-ShardingSphere-UI-YAMLÔ¶³Ì´úÂëÖ´ÐÐ.Apache¹Ù·½Ðû²¼ÁËShardingSphereа汾ÐÞ¸´ÁËÒ»¸öYAMLÆÊÎöµ¼ÖµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-1947£©¡£¡£¡£¡£¡£¡£¡£ApacheShardingSphereÊÇÒ»Ì׿ªÔ´µÄÂþÑÜʽÊý¾Ý¿âÖÐÐļþ½â¾ö¼Æ»®×é³ÉµÄÉú̬Ȧ£¬£¬ £¬£¬£¬ËüÓÉSharding-JDBC¡¢Sharding-ProxyºÍSharding-Sidecar£¨ÍýÏëÖУ©Õâ3¿îÏ໥×ÔÁ¦£¬£¬ £¬£¬£¬È´ÓÖÄܹ»»ìÏý°²ÅÅÅäºÏʹÓõIJúÆ·×é³É¡£¡£¡£¡£¡£¡£¡£ËüÃǾùÌṩ±ê×¼»¯µÄÊý¾Ý·ÖƬ¡¢ÂþÑÜʽÊÂÎñºÍÊý¾Ý¿âÖÎÀí¹¦Ð§£¬£¬ £¬£¬£¬¿ÉÊÊÓÃÓÚÈçJavaͬ¹¹¡¢Òì¹¹ÓïÑÔ¡¢ÔÆÔ­ÉúµÈÖÖÖÖ¶àÑù»¯µÄÓ¦Óó¡¾°¡£¡£¡£¡£¡£¡£¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß¾ÙÐÐ×¢Èë¹¥»÷£¬£¬ £¬£¬£¬²¢ÇÒ͵ȡÊý¾Ý¿âÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Apache_SkyWalking_GraphQL½Ó¿Ú_SQL×¢Èë[CVE-2020-9483/CVE-2020-13921][CNNVD-202006-1863/CNNVD-202008-152]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÊÔͼͨ¹ýApache_SkyWalkingGraphQL½Ó¿ÚµÄSQL×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£ApacheSkyWalkingÊÇÒ»¿îÓ¦ÓÃÐÔÄÜ¼à¿Ø£¨APM£©¹¤¾ß£¬£¬ £¬£¬£¬¶Ô΢ЧÀÍ¡¢ÔÆÔ­ÉúºÍÈÝÆ÷»¯Ó¦ÓÃÌṩ×Ô¶¯»¯¡¢¸ßÐÔÄÜµÄ¼à¿Ø¼Æ»®¡£¡£¡£¡£¡£¡£¡£Æä¹Ù·½ÍøÕ¾ÏÔʾ£¬£¬ £¬£¬£¬´ó×ڵĺ£ÄÚ»¥ÁªÍø¡¢ÒøÐС¢Ãñº½µÈÁìÓòµÄ¹«Ë¾ÔÚʹÓô˹¤¾ß¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýApacheSkyWalkingĬÈÏ¿ª·ÅµÄδÊÚȨGraphQL½Ó¿Ú½á¹¹¶ñÒâÇëÇó°ü¾ÙÐÐ×¢È룬£¬ £¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÔì³ÉÃô¸ÐÊý¾Ý×ß©¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì[CVE-2021-26855]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Ä¿½ñÖ÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì[CVE-2021-26855][CNNVD-202103-192]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Ä¿½ñÖ÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷¸ÃÎó²îÊÇExchangeÖеÄí§ÒâÎļþдÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÐèÒª¾ÙÐÐÉí·ÝÈÏÖ¤£¬£¬ £¬£¬£¬Ê¹ÓôËÎó²î¿ÉÒÔ½«ÎļþдÈëЧÀÍÆ÷ÉϵÄÈκη¾¶¡£¡£¡£¡£¡£¡£¡£²¢¿ÉÒÔÁ¬ÏµÊ¹ÓÃCVE-2021-26855SSRFÎó²î»òÈÆ¹ýȨÏÞÈÏÖ¤¾ÙÐÐÎļþдÈë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_Éè¼ÆÈ±ÏÝ_ÌìÈÚÐÅÊý¾Ý·À×ß©ϵͳ_ԽȨÐÞ¸ÄÖÎÀíÔ±_Âß¼­/Éè¼Æ¹ýʧ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÌìÈÚÐÅÊý¾Ý·À×ß©ϵͳµÄԽȨÎó²î¾ÙÐÐÖÎÀíÔ±ÃÜÂëÐ޸ģ» £»£»£»£»ÌìÈÚÐÅÊý¾Ý·À×ß©ϵͳ(¼ò³Æ:TopDLP)ÊÇÒÔÉî¶ÈÄÚÈÝʶ±ðÊÖÒÕΪ½¹µã,ÔÚÊý¾Ý´æ´¢¡¢´«ÊäºÍʹÓÃÀú³ÌÖÐ,·¢Ã÷²¢Ê¶±ðÃô¸ÐÊý¾ÝÒþ»¼,È·±£Ãô¸ÐÊý¾ÝÕýµ±Ê¹ÓÃ,±ÜÃâÃô¸ÐÊý¾Ý×ß©µÄÊý¾ÝÇå¾²±£» £»£»£»£»¤ÏµÍ³¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange-Server_´úÂëÖ´ÐÐ[CVE-2020-16875][CNNVD-202009-374]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÓÉÓÚ¶Ôcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·£¬£¬ £¬£¬£¬MicrosoftExchangeЧÀÍÆ÷Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÓû§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£Ê¹ÓôËÎó²îÐèÒªÒÑͨ¹ýÉí·ÝÑéÖ¤µÄÓû§¾ßÓÐÊܵ½ÍþвµÄÌØ¶¨Exchange½ÇÉ«¡£¡£¡£¡£¡£¡£¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕýMicrosoftExchange´¦Öóͷ£cmdlet²ÎÊýµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_CLTPHP_V5.8_ºǫ́í§ÒâÎļþɾ³ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CLTPHPÊÇ»ùÓÚThinkPHP5¿ª·¢£¬£¬ £¬£¬£¬ºǫ́½ÓÄÉLayui¿ò¼ÜµÄÄÚÈÝÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¡£CLTPHP5.8¼°Ö®Ç°°æ±¾±£´æºǫ́í§ÒâÎļþɾ³ýÎó²î£¬£¬ £¬£¬£¬Í¨¹ý½á¹¹¶ñÒâpayload¹¥»÷Õß¿Éɾ³ýϵͳÖеÄí§ÒâÎļþ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SpamTitanÍø¹Ø_´úÂëÖ´ÐÐ[CVE-2020-11699][CNNVD-202009-1082]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SpamTitanÍø¹ØÊǹ¦Ð§Ç¿Ê¢µÄ·´À¬»øÓʼþ×°±¸£¬£¬ £¬£¬£¬ËüÎªÍøÂçÖÎÀíÔ±ÌṩÁËÆÕ±éµÄ¹¤¾ßÀ´¿ØÖÆÓʼþÁ÷²¢±ÜÃâÓк¦µÄµç×ÓÓʼþºÍ¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ±£´æ´úÂëȱÏÝ£¬£¬ £¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâpayload£¬£¬ £¬£¬£¬Ê¹µÃÄ¿µÄÖ÷»úÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_AXIS_´úÂëÖ´ÐÐ[CVE-2019-0227]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_Apache_Axis_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£ApacheAxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWebЧÀͼܹ¹¡£¡£¡£¡£¡£¡£¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAPЧÀÍÆ÷£¬£¬ £¬£¬£¬ÒÔ¼°ÖÖÖÖ¹«ÓÃЧÀͼ°API£¬£¬ £¬£¬£¬ÒÔÌìÉúºÍ°²ÅÅWebЧÀÍÓ¦Óᣡ£¡£¡£¡£¡£¡£Axis¸½´øµÄĬÈÏЧÀÍStockQuoteService.jws°üÀ¨Ò»¸öÓ²±àÂëµÄHTTPURL£¬£¬ £¬£¬£¬¿ÉÓÃÓÚ´¥·¢HTTPÇëÇ󡣡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓòÃû£¨www.xmltoday.com£©½ÓÊÜ»òÕßͨ¹ýARPÓÕÆ­Ð§ÀÍÆ÷´Ó¶øÖ´ÐÐMITM¹¥»÷£¬£¬ £¬£¬£¬²¢½«HTTPÇëÇóÖØ¶¨Ïòµ½¶ñÒâWebЧÀÍÆ÷£¬£¬ £¬£¬£¬ÔÚApacheAxisЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬ £¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Weblogic_wls-wsat_´úÂëÖ´ÐÐ[CVE-2017-3506/10271]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»úÌᳫWeblogicwls-wsatÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£OracleWeblogicServerÊÇÓ¦ÓóÌÐòЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£OracleWeblogicServer10.3.6.0¡¢12.2.1.2¡¢12.2.1.1¡¢12.1.3.0°æ±¾±£´æ¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£WeblogicWLS×é¼þÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÏòWeblogicЧÀÍÆ÷·¢ËÍÈ«ÐĽṹµÄHTTP¶ñÒâÇëÇ󣬣¬ £¬£¬£¬¹¥»÷ÀֳɿÉÒÔ»ñÈ¡µ½Ð§ÀÍÆ÷µÄWebshell£¬£¬ £¬£¬£¬½øÒ»²½¿ÉÒÔ»ñµÃÄ¿µÄЧÀÍÆ÷µÄ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£¡£ÊµÑéʹÓÃWeblogicwls-wsatÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_TP-Link_NC220_setsysname.fcgi_ÏÂÁî×¢Èë[CVE-2020-12109][CNNVD-202005-007]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TP-LinkNC200µÈ¶¼ÊÇÖйúÆÕÁª£¨TP-Link£©¹«Ë¾µÄÒ»¿îÍøÂçÉãÏñ»ú¡£¡£¡£¡£¡£¡£¡£¶à¿îTP-Link²úÆ·ÖеÄipcamera¶þ½øÖÆÎļþµÄswSystemSetProductAliasCheckÒªÁì±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖúÌØÖÆHTTPPOSTÇëÇóʹÓøÃÎó²îÒÔrootÓû§Éí·ÝÔÚϵͳÉÏÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_Éí·ÝÑéÖ¤ÈÆ¹ý[CVE-2020-11989][CNNVD-202006-1556]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬ £¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬£¬ £¬£¬£¬ÊÚȨµÈ¡£¡£¡£¡£¡£¡£¡£¹ØÓÚApacheShiro1.5.3֮ǰµÄ°æ±¾£¬£¬ £¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬£¬ £¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Nagios_XI_mibs.php_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-5791][CNNVD-202010-1115]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

NagiosXIÊÇÒ»¸ö½¨ÉèÔÚNagios½¹µãÉÏµÄÆóÒµ¼¶¼à²âºÍ±¨¾¯¼Æ»®µÄ¿ªÔ´×é¼þ¡£¡£¡£¡£¡£¡£¡£¹¦Ð§°üÀ¨PHPÍøÕ¾½çÃæ¡¢×ÛºÏÌåÏÖͼ¡¢¿É¶¨ÖƵÄÒDZí°å¡¢ÍøÂç½á¹¹¡¢ÉèÖÃGUI(ͼÐÎÓû§½Ó¿Ú)¡¢Óû§ÖÎÀíµÈ¡£¡£¡£¡£¡£¡£¡£NagiosXI5.7.3Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÇå¾²Îó²î£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÒÔ¡°apache¡±Óû§Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_OFBiz_rmi·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2021-26295][CNNVD-202103-1262]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheOFBiz±£´æRMI·´ÐòÁл¯Ç°Ì¨ÏÂÁîÖ´ÐУ¬£¬ £¬£¬£¬Î´¾­Éí·ÝÑéÖ¤¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬ £¬£¬£¬´¥·¢·´ÐòÁл¯£¬£¬ £¬£¬£¬´Ó¶øÔì³Éí§Òâ´úÂëÖ´ÐУ¬£¬ £¬£¬£¬¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÉèÖÃȱÏÝ_ÉîÐÅ·þ_SSLVPN_changetelnum.csp_í§ÒâÕË»§°ó¶¨ÊÖ»úºÅÐÞ¸Ä

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÉîÐÅ·þSSLVPNµÄchangetelnum.csp±£´æÂß¼­Ô½È¨Îó²î£¬£¬ £¬£¬£¬¹¥»÷ÕߵǼÀֳɺó¿ÉÐÞ¸Äí§ÒâÓû§°ó¶¨µÄÊÖ»úºÅÂë¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖУ¬£¬ £¬£¬£¬Ò»Ð©Ê¾ÀýDAGûÓÐ׼ȷÕûÀíÓû§ÌṩµÄ²ÎÊý£¬£¬ £¬£¬£¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSÏÂÁî×¢ÈëµÄÓ°Ïì¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_v1.7.1ÒÔÏÂ_·ÇÊÚȨ»á¼û[CVE-2020-17523][CNNVD-202102-238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬£¬ £¬£¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬£¬ £¬£¬£¬ÊÚȨµÈ¡£¡£¡£¡£¡£¡£¡£¹ØÓÚApacheShiro1.7.1֮ǰµÄ°æ±¾£¬£¬ £¬£¬£¬µ±½«ApacheShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬£¬ £¬£¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220913