ÿÖÜÉý¼¶Í¨¸æ-2023-02-28

Ðû²¼Ê±¼ä 2023-02-28

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÏÂÁîÖ´ÐÐ_GLPI_htmLawedTest.php

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃGLPIÖÐhtmLawedTest.php´¦µÄÎó²î£¬¾ÙÐÐÔ¶³Ìí§ÒâÏÂÁîÖ´ÐС£GLPIÊÇСÎÒ˽¼Ò¿ª·¢ÕßµÄÒ»¿î¿ªÔ´ITºÍ×ʲúÖÎÀíÈí¼þ¡£¸ÃÈí¼þÌṩ¹¦Ð§ÖÜÈ«µÄIT×ÊÔ´ÖÎÀí½Ó¿Ú£¬Äã¿ÉÒÔÓÃËüÀ´½¨ÉèÊý¾Ý¿âÖÜÈ«ÖÎÀíITµÄµçÄÔ£¬ÏÔʾÆ÷£¬·þÎñÆ÷£¬´òÓ¡»ú£¬ÍøÂç×°±¸£¬µç»°£¬ÉõÖÁÎø¹ÄºÍÄ«ºÐµÈ¡£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_δÊÚȨ»á¼û_Apache_AXIS_AdminService

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApacheAxisδÊÚȨ»á¼ûÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£ApacheAxisÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°ÖÖÖÖ¹«Ó÷þÎñ¼°API£¬ÒÔÌìÉúºÍ°²ÅÅWeb·þÎñÓ¦Óá£Îó²îʵÖÊÊÇÖÎÀíÔ±¶ÔAdminServiceµÄÉèÖùýʧ¡£µ±enableRemoteAdminÊôÐÔÉèÖÃΪtrueʱ£¬¹¥»÷Õß¿ÉÒԽṹWebServiceŲÓÃfreemarker×é¼þÖеÄtemplate.utility.ExecuteÀ࣬Զ³ÌʹÓÃAdminService½Ó¿Ú¾ÙÐÐWebServiceÐû²¼£¬Ôٴλá¼ûÌìÉúµÄWebService½Ó¿Ú£¬´«ÈëÒªÖ´ÐеÄÏÂÁ¾Í¿ÉÒÔ¾ÙÐÐÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îµÄʹÓá£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_IBM_Aspera_Faspex[CVE-2022-47986]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

IBMAsperaFaspexÊÇÒ»¸ö»ùÓÚIBMAspera¸ßËÙ´«Êä·þÎñÆ÷¹¹½¨µÄÎļþ½»Á÷Ó¦ÓóÌÐò£¬×÷Ϊ¼¯Öд«Êä½â¾ö¼Æ»®¡£½èÖú»ùÓÚWebµÄGUI£¬FaspexΪFASP¸ßËÙ´«ÊäÌṩÁ˸߼¶ÖÎÀíÑ¡ÏÒÔÆ¥ÅäÏà¹ØµÄÊÂÇéÁ÷³Ì¡£ÓÉÓÚYAML·´ÐòÁл¯È±ÏÝ£¬IBMAsperaFaspex¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂ롣ͨ¹ý·¢ËÍÌØÊâÖÆ×÷µÄ¹ýʱAPIŲÓ㬹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚϵͳÉÏÖ´ÐÐí§Òâ´úÂë¡£Ó°Ïì°æ±¾£ºFaspex<=4.4.2

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Spring_Boot_logging.config

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃActuatorµÄ/evn½Ó¿Úͨ¹ýlogging.config²ÎÊýʵÑéÔ¶³Ì´úÂëÖ´ÐС£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØϵͳÊý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØÐí¶àÐí¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬¿ÉÒÔÉó²éÓ¦ÓÃÉèÖõÄÏêϸÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20230228

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Discuz_X_uc_center

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Discuz!MLϵͳÖУ¬Í¨Êºǫ́ÐÞ¸ÄUcenterÊý¾Ý¿âÅþÁ¬ÐÅÏ¢£¬¿É½«¶ñÒâ´úÂëдÈëconfig/config_ucenter.phpÎļþÖУ¬µ¼Ö´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Discuz!X3.4

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Discuz!MLϵͳװÖúóδÉÏ°¶ºǫ́ʱ£¬¿ÉʹÓÃÎļþɾ³ýÎó²îɾµôinstall.lockÎļþ£¬Èƹý¶Ô×°ÖÃÍê³ÉµÄÅжÏÄܹ»ÔÙ¾ÙÐÐ×°ÖõÄÀú³Ì£¬È»ºó½«¶ñÒâ´úÂëдÈëÉèÖÃÎļþÖдӶøÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_Phpcms:V9.5.8_ºǫ́ÖÎÀí

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCMS-Phpcms:V9.5.8ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬¸ÃÎó²îʹÓÃcontent.phpÎļþ½á¹¹¶ñÒâpayload£¬´Ó¶øÔì³É´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_SpamTitanÍø¹Ø[CVE-2020-11699][CNNVD-202009-1082]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SpamTitanÍø¹ØÊǹ¦Ð§Ç¿Ê¢µÄ·´À¬»øÓʼþ×°±¸£¬ËüΪÍøÂçÖÎÀíÔ±ÌṩÁËÆÕ±éµÄ¹¤¾ßÀ´¿ØÖÆÓʼþÁ÷²¢±ÜÃâÓк¦µÄµç×ÓÓʼþºÍ¶ñÒâÈí¼þ¡£ÓÉÓÚ±£´æ´úÂëȱÏÝ£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâpayload£¬Ê¹µÃÄ¿µÄÖ÷»úÖ´ÐжñÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Õì̽ɨÃè_ɨÃèÆ÷_DisBuster

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

DisBusterÊÇÉø͸²âÊÔÀú³ÌÖг£ÓõÄɨÃ蹤¾ß£¬¿ÉÒÔ×Ô½ç˵¼ÓÔØ×Ô½ç˵×Öµä¶ÔÄ¿µÄ¾ÙÐÐĿ¼»òÒ³ÃæɨÃèºÍ±¬ÆÆ¡£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Weblogic_ForeignOpaqueReference×é¼þ_JNDI×¢Èë_´úÂëÖ´ÐÐ[CVE-2023-21839]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨£¬ÓÃÓÚÔÚÍâµØºÍÔƶ˿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò£¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£ÓÉÓÚForeignOpaqueReferenceÀà±£´æÇå¾²ÎÊÌ⣬CVE-2023-21839Îó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3/IIOPЭÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°Ïì¹æÄ££ºOracleWebLogicServer12.2.1.3.0OracleWebLogicServer12.2.1.4.0OracleWebLogicServer14.1.1.0.0

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Apache_Log4j2_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-44228][CNNVD-202112-799]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheLog4j2ÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£ÔÚApacheLog4j22.15.0_rc1֮ǰµÄ2.x°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔ¶³ÌÖ´ÐÐí§Òâ´úÂë

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_SQL×¢Èë_Django_kind_lookup_name[CVE-2022-34265][CNNVD-202207-347]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

DjangoÊÇÒ»¸ö»ùÓÚPythonµÄ¿ªÔ´WebÓ¦Óÿò¼Ü¡£Django±£´æÒ»¸öSQL×¢ÈëÎó²î£¨CVE-2022-34265£©¡£ÔÚÊÜÓ°ÏìµÄDjango°æ±¾£¨3.2.14¡¢4.0.6֮ǰµÄ°æ±¾£©ÖУ¬¿ÉÒÔͨ¹ýת´ï¶ñÒâÊý¾Ý×÷Ϊkind/lookup_nameµÄÖµ£¬ÈôÊÇÓ¦ÓóÌÐòÔÚ½«ÕâЩ²ÎÊýת´ï¸øTrunc()ºÍExtract()Êý¾Ý¿âº¯Êý£¨ÈÕÆÚº¯Êý£©Ö®Ç°Ã»Óо­ÓÉÊäÈë¹ýÂË»òתÒ壬ÔòÈÝÒ×Êܵ½SQL×¢Èë¹¥»÷¡£Í¨¹ýʹÓôËÎó²î£¬µÚÈý·½¿ÉÒÔÏòÊý¾Ý¿â·¢ËÍÏÂÁîÒÔ»á¼ûδ¾­ÊÚȨµÄÊý¾Ý»òɾ³ýÊý¾Ý¿âµÈ¶ñÒâÐÐΪ¡£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_·´ÐòÁл¯_Weblogic_T3ЭÒé[CVE-2020-14756][CVE-2020-14756/CVE-2021-2394]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨£¬ÓÃÓÚÔÚÍâµØºÍÔƶ˿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò£¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2020-2555Îó²î¿ÉÒÔÈƹýºÚÃûµ¥Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»Çå¾²µÄextractÒªÁ죬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°Ïì¹æÄ££ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_jolokia_logback_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃActuatorµÄ/jolokia½Ó¿ÚŲÓÃch.qos.logback.classic.jmx.JMXConfiguratorÀàµÄreloadByURLÒªÁìÉèÖÃÍⲿÈÕÖ¾ÉèÖÃurlµØµã¡£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØϵͳÊý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØÐí¶àÐí¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬¿ÉÒÔÉó²éÓ¦ÓÃÉèÖõÄÏêϸÐÅÏ¢¡£JolokiaÔÊÐíͨ¹ýHTTP»á¼ûËùÓÐÒÑ×¢²áµÄMBean£¬Í¬Ê±¿ÉÒÔʹÓÃURLÁгöËùÓпÉÓõÄMBeans²Ù×÷¡£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó

Çå¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂíʵÑéÅþÁ¬¿ó³Ø£¬Êܺ¦Ö÷»ú±äÂý¡£

¸üÐÂʱ¼ä£º

20230228

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_WebLogic_·´ÐòÁл¯Îó²î[CVE-2018-3252][CNNVD-201810-843]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWeblogic½á¹¹¶ñÒâ·´ÐòÁдúÂëÖ´ÐÐí§ÒâÏÂÁOracleWeblogicServerÊÇÓ¦ÓóÌÐò·þÎñÆ÷¡£WeblogicÓ¦Ó÷þÎñÆ÷µÄApacheConnectorÄ£¿éÖеÄmod_wlδ¶ÔÓû§Ìá½»µÄÊäÈëÊý¾Ý¾ÙÐÐ׼ȷ¼ì²é£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²î¾ÙÐлº³åÇøÒç³ö¹¥»÷£¬¿Éµ¼Ö¾ܾø·þÎñ»òí§Òâ´úÂëÖ´Ðй¥»÷¡£¹¥»÷Õß¿ÉÒÔÌá½»°üÀ¨³¬³¤Êý¾ÝµÄPOSTÇëÇó´¥·¢´ËÎó²î£¬È«ÐĹ¹½¨Ìá½»Êý¾Ý¿Éµ¼ÖÂÒÔÓ¦ÓóÌÐòȨÏÞÖ´ÐÐí§ÒâÖ¸Á»ñµÃ·þÎñÆ÷µÄ¿ØÖÆȨ¡£

¸üÐÂʱ¼ä£º

20230228