ÿÖÜÉý¼¶Í¨¸æ-2022-10-04

Ðû²¼Ê±¼ä 2022-10-04

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_VMware_vCenter_Server_SSRF·þÎñ¶ËÇëÇóαÔì[CVE-2021-21973][CNNVD-202102-1559]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃVMwarevCenterServerδ¶ÔÓû§ÌṩµÄÊäÈëÑéÖ¤µÄÎó²î£¬ÔÚ¡°vcIP¡±½á¹¹¶ñÒâip£¬ÓÕÆ­Ó¦ÓóÌÐòÏòí§ÒâϵͳÌᳫÇëÇóʵÏÖÄÚÍøɨÃ裬´Ó¶ø»ñÈ¡ÄÚÍøÐÅÏ¢£¬µ¼ÖÂÐÅϢй¶¡£VMwarevCenterServer£¨ÒÔÇ°³ÆΪVMwareVirtualCenter£©£¬¿É¼¯ÖÐÖÎÀíVMwarevSphereÇéÐΣ¬ÓëÆäËûÖÎÀíƽ̨Ïà±È£¬¼«´óµØÌá¸ßÁËITÖÎÀíÔ±¶ÔÐéÄâÇéÐεĿØÖÆ¡£

¸üÐÂʱ¼ä£º

20221004

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ToTolink_t6_firmware_ÏÂÁîÖ´ÐÐ[CVE-2022-38828]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃToTolink_t6_firmwareV4.1.5cu.709_B20210518ÖÐcstecgi.cgi´¦µÄÎó²î£¬½á¹¹¶ñÒâÏÂÁî¾ÙÐÐÏÂÁî×¢Èë¹¥»÷£¬´Ó¶ø»ñÈ¡Ä¿µÄϵͳȨÏÞ¡£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_RDP_ɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úʹÓÃNMAPͨ¹ýRDPЭÒé»ñÈ¡ÅÌËã»úÐÅÏ¢µÄÐÐΪ¡£¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004

 

ÊÂÎñÃû³Æ£º

TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_RDP_ɨÃè

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓöÔÄ¿µÄÖ÷»úʹÓÃNMAPͨ¹ýSMBЭÒé»ñÈ¡ÅÌËã»úÐÅÏ¢µÄÐÐΪ¡£¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ThinkPHP5.15.2_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃThinkPHP5Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬¸ÃÎó²îÊÇÓÉÓÚThinkPHP5¿ò¼Üµ×²ã¶Ô¿ØÖÆÆ÷Ãû¹ýÂ˲»ÑÏ£¬´Ó¶øÈù¥»÷Õß¿ÉÒÔͨ¹ýurlŲÓõ½ThinkPHP¿ò¼ÜÄÚ²¿µÄÃô¸Ðº¯Êý£¬½ø¶øµ¼ÖÂgetshellÎó²î¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ThinkPHPÊÇÒ»¸ö¿ìËÙ¡¢¼æÈݲ¢ÇÒ¼òÆÓµÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£

¸üÐÂʱ¼ä£º

20221004


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jolokia_JNDI_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃJolokiaµÄJNDI½Ó¿Ú½á¹¹¶ñÒâldapºÍrmiÇëÇ󣬴ӶøÖ´ÐÐí§Òâ´úÂë¡£JolokiaÊÇÒ»¸öJMX-HTTPÅþÁ¬Æ÷£¬¿ÉÒÔÌæ»»JSR-160ÅþÁ¬Æ÷¡£

¸üÐÂʱ¼ä£º

20221004

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ThinkPHP5.0.x_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2018-20062][CNNVD-201812-489]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃThinkPHP¿ò¼ÜµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬ÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£ThinkPHPÊÇÒ»¸öÊ¢ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü

¸üÐÂʱ¼ä£º

20221004

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_Social_Warfare_Plugin_before3.5.3_Îļþ°üÀ¨

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWordPressµÄSocial_Warfare²å¼þ¾ÙÐÐÔ¶³Ì´úÂëÖ´ÐУ¬¸Ã²å¼þûÓжԴ«Èë²ÎÊý¾ÙÐÐÑÏ¿á¿ØÖÆÒÔ¼°¹ýÂË£¬µ¼Ö¹¥»÷Õ߿ɽṹ¶ñÒâpayload£¬ÎÞÐèºǫ́ȨÏÞ£¬Ö±½ÓÔì³ÉÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£social-warfareÊÇÒ»¿îWordPressÉç½»·ÖÏí°´Å¥²å¼þ¡£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON_databind_caucho_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬Í¨¹ýcom.caucho.config.types.ResourceRefÀà½á¹¹¶ñÒâjava´úÂë¡£jackson-databindÊÇÁ¥ÊôFasterXMLÏîÄ¿×éϵÄJSON´¦Öóͷ£¿â¡£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON_Shiro_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬Í¨¹ýshiro-coreÀà´¥·¢JNDIÔ¶³ÌÀà¼ÓÔزÙ×÷¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öóͷ£¹¤¾ß¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄ½¹µã×é¼þÖ®Ò»¡£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_WebLogic_´úÂëÖ´ÐÐ[CVE-2022-21350]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWeblogicÖеÄOracleFusionMiddleware£¨×é¼þ£ºCore£©ÖеÄÎó²î½á¹¹¶ñÒâ·´ÐòÁдúÂëͨ¹ýT3»á¼ûÍøÂçÀ´¾ÙÐй¥»÷£»WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò»£¬±»³ÆΪҵ½ç×î¼ÑµÄÓ¦ÓóÌÐò·þÎñÆ÷£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò£¬Ö§³Öй¦Ð§£¬¿É½µµÍÔËÓª±¾Ç®£¬Ìá¸ßÐÔÄÜ£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£T3ЭÒéÊÇÓÃÓÚWeblogic·þÎñÆ÷ºÍÆäËûJavaApplicationÖ®¼ä´«ÊäÐÅÏ¢µÄЭÒ飬ÊÇʵÏÖRMIÔ¶³ÌÀú³ÌŲÓõÄרÓÐЭÒ飬ÆäÔÊÐí¿Í»§¶Ë¾ÙÐÐJNDIŲÓá£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

HTTP_ÍøÂçɨÃè_Ìì¾µ6.0ɨÃèÆ÷

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãµÄÖ÷»úÕýÔÚʹÓÃÌì¾µ6.0ɨÃ蹤¾ß¶ÔÄ¿µÄIPµØµã¾ÙÐÐÎó²îɨÃè¡£Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳÊÇÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍø¹«Ë¾×ÔÖ÷Ñз¢µÄ»ùÓÚÍøÂçµÄÇå¾²ÐÔÄÜÆÀ¹ÀÆÊÎöϵͳ£¬¿ÉÒÔ¶ÔÍøÂçÖеÄÖÖÖÖϵͳ¡¢×°±¸ºÍÊý¾Ý¿â¾ÙÐÐÎó²îɨÃ裬¶ÔÍøÂç¾ÙÐÐÓÐÓõÄÆÀ¹À£¬²¢Ìá³ö½¨ÉèÐԵĽâ¾ö¼Æ»®¡£¿ÉÄܻᵼÖÂÄ¿µÄϵͳй¶ijЩÃô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_WebLogic_Blind_XXE×¢Èë[CVE-2019-2647]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWebLogic_Blind_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£WebLogic_Blind_XXE×¢ÈëÎó²î£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬´Ó¶øʵÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlindXXE¹¥»÷£¬¶ÁÈ¡Ä¿µÄϵͳÎļþ¡£

¸üÐÂʱ¼ä£º

20221004

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Adobe_Coldfusion_JNBridge_listener_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2019-7839][CNNVD-201906-514]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÕýÔÚʹÓÃAdobeColdfusionµÄJNBridge×é¼þµÄÎó²î½á¹¹¶ñÒâjava´úÂ룬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£AdobeColdFusionÊÇÒ»¸öÉÌÓõĿìËÙ¿ª·¢Æ½Ì¨¡£Ëü¿ÉÒÔ×÷Ϊһ¸ö¿ª·¢Æ½Ì¨Ê¹Óã¬Ò²¿ÉÒÔÌṩFlashÔ¶³Ì·þÎñ»òÕß×÷ΪAdobeFlexÓ¦Óõĺǫ́·þÎñÆ÷¡£ÓÉÓÚJNBridge×é¼þ±£´æȱÏÝ£¬¶øColdFusionĬÈÏ¿ªÆôJNBridge×é¼þ£¬¿ÉÄܵ¼Ö´úÂëÖ´ÐÐÎó²î¡£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Cacti_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-8813][CNNVD-202002-1075]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚͨ¹ýÔÚCacti1.2.8¼°Ö®Ç°µÄ°æ±¾µÄ·Ã¿ÍÒ³Ãæ¡°graph_realtime.php¡±´¦Î´¶ÔCookie´¦µÄÊäÈë¾ÙÐÐÑéÖ¤µÄÎó²î£¬½á¹¹¶ñÒâ´úÂë´Ó¶øÖ´ÐÐÔ¶³ÌÏÂÁî¡££¬CactiÊÇÒ»Ì×»ùÓÚPHP,MySQL,SNMP¼°RRDTool¿ª·¢µÄÍøÂçÁ÷Á¿¼à²âͼÐÎÆÊÎö¹¤¾ß¡£Ëüͨ¹ýsnmpgetÀ´»ñÈ¡Êý¾Ý£¬Ê¹ÓÃRRDtool»æ»æͼÐΣ¬²¢ÇÒÍêÈ«¿ÉÒÔ²»ÐèÒªÏàʶRRDtoolÖØ´óµÄ²ÎÊý¡£

¸üÐÂʱ¼ä£º

20221004


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jellyfin_SSRF_·þÎñ¶ËÇëÇóαÔì[CVE-2021-29490]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´Ö÷»úipÕýÔÚʹÓÃJellyfin¼°10.7.3֮ǰµÄSSRFÎó²î£¬½á¹¹¶ñÒâÇëÇó¸ÃÎó²î̽²âÄÚÍøÐÅÏ¢¡£JellyfinÊÇÒ»¸öÃâ·ÑµÄÈí¼þýϵһÇС£

¸üÐÂʱ¼ä£º

20221004

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_weblogic_·þÎñ¶ËÇëÇóαÔì[CVE-2014-4210]

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃweblogic·þÎñ¶ËÇëÇóαÔìÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£OracleWebLogicServerÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚÔÆÇéÐκ͹ŰåÇéÐεÄÓ¦Ó÷þÎñÆ÷£¬ËüÌṩÁËÒ»¸öÏÖ´úÇáÐÍ¿ª·¢Æ½Ì¨£¬Ö§³ÖÓ¦Óôӿª·¢µ½Éú²úµÄÕû¸öÉúÃüÖÜÆÚÖÎÀí£¬²¢¼ò»¯ÁËÓ¦Óõİ²ÅźÍÖÎÀí¡£OracleFusionMiddleware10.0.2.0ºÍ10.3.6.0°æ±¾µÄOracleWebLogicServer×é¼þÖеÄWLS-WebServices×Ó×é¼þ±£´æÇå¾²Îó²î¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²î¶ÁÈ¡Êý¾Ý£¬Ó°ÏìÊý¾ÝµÄ±£ÃÜÐÔ¡£»ñÈ¡ÄÚÍøÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004