ÿÖÜÉý¼¶Í¨¸æ-2022-08-23

Ðû²¼Ê±¼ä 2022-08-23
ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_Òç³ö¹¥»÷_GPON·ÓÉÆ÷_ÈÏÖ¤Õ»Òç³öCVE-2019-3921][CNNVD-201903-081]

Äþ¾²ÀàÐÍ£º

»º³åÒç³ö

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHTTP_GPON_·ÓÉÆ÷_ÈÏÖ¤Õ»Òç³ö©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SonicWall_Global_Management_System_ÈÎÒâ´úÂëÖ´ÐÐ[CVE-2018-9866][CNNVD-201808-124]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃCVE-2018-9866©¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£SonicWallGlobalManagementSystem£¨GMS£©ÊÇ¿ìËÙ²¿ÊðºÍ¼¯ÖйÜÀíDellSonicWALL·À»ðǽ¡¢·´À¬»øÓʼþ¡¢±¸·ÝºÍ»Ö¸´ÒÔ¼°Äþ¾²Ô¶³Ì·ÃÎʽâ¾ö·½°¸µÄÒ»Ì×¹ÜÀíϵͳ¡£SonicWallGMS8.1¼°Ö®Ç°°æ±¾ÖдæÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÑéÖ¤Óû§Ìá½»µÄÓÃÓÚXML-RPCµ÷ÓõIJÎÊý¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø鶴ִÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

TCP_Òç³ö¹¥»÷_HelixServer_DESCRIBEÇëÇóÔ¶³Ì¶ÑÒç³ö[CVE-2006-6026]

Äþ¾²ÀàÐÍ£º

»º³åÒç³ö

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHelixServerDESCRIBEÇëÇóÔ¶³Ì¶ÑÒç³ö©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£HelixServerÊÇRMýÌåÁ÷·þÎñÆ÷REALµÄ¿ªÔ´°æ±¾£¬Ö§³ÖRTSPЭÒ飬֧³ÖRM¡¢MP3µÈ¸ñʽ¡£HelixServer¿ÉÒÔ¹¹½¨¸ßÐÔÄܵÄÁ÷ýÌå·þÎñÆ÷£¬Ö§³Ö¶à¸ñʽ¡¢¿çƽ̨£¬¿ÉÒÔ½«¸ßÖÊÁ¿µÄ¶àýÌåÄÚÈÝ·¢µ½ÈκÎÍøÂçÄܹ»´¥¼°µÄµØ·½¡£Ö§³ÖÒƶ¯´«Êä³ß¶È£¬°üÂÞ3GPPʵʱѹËõ£¬Âú×ãÓû§µÄ²îÒìµÄ·þÎñÐèÇó¡£RealNetworksHelixServerºÍHelixMobileServer11.1.3֮ǰµÄ°æ±¾£¬ÒÔ¼°HelixDNAServer11.0ºÍ11.1ÖдæÔÚ»ùÓڶѵĻº³åÇøÒç³ö£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý°üÂÞÎÞЧLoadTestPassword×ֶεÄÃèÊöÇëÇóÔì³É¾Ü¾ø·þÎñ£¨Ó¦Ó÷¨Ê½Í߽⣩»òÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

TCP_ÆäËü×¢Èë_Courier_IMAP_4.0.1_XMAILDIR±äÁ¿Ô¶³ÌShellÃüÁî×¢Èë

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃCourierIMAPXMAILDIR±äÁ¿Ô¶³ÌShellÃüÁî×¢È멶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£Courier-IMAPÊÇCourierÓʼþϵͳÖеÄIMAP·þÎñ·¨Ê½¡£Courier-IMAP¶Ô±äÁ¿Êý¾ÝµÄ¹ýÂËÉÏ´æÔÚ©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓôË©¶´ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

TCP_Òç³ö¹¥»÷_CA_BrightStor_ARCserve_Backup·þÎñÔ¶³Ì»º³åÇøÒç³ö[CVE-2006-6076]

Äþ¾²ÀàÐÍ£º

»º³åÒç³ö

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃCABrightStorARCserveBackup·þÎñÔ¶³Ì»º³åÇøÒç³ö©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£CABrightStorARCserveBackup11.5ÒÔ¼°¸üÔç°æ±¾ÖеÄTapeEngine´æÔÚ»º³åÇøÒç³ö©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý¶ÔTCP¶Ë¿Ú6502µÄijЩRPCÇëÇóÀ´Ö´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ÖÂÔ¶OA_E-Bridge_saveYZJFile_ÈÎÒâÎļþ¶ÁÈ¡

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

δÊÚȨÈÎÒâÎļþ¶ÁÈ¡,/wxjsapi/saveYZJFile½Ó¿Ú»ñÈ¡filepath,ÊäÈëÎļþ·¾¶->¶ÁÈ¡ÎļþÄÚÈÝ¡£·µ»ØÊý¾Ý°üÄÚ·ºÆðÁË·¨Ê½µÄ¾ø¶Ô·¾¶,¹¥»÷Õß¿ÉÒÔͨ¹ý·µ»ØÄÚÈÝʶ±ð·¨Ê½ÔËÐз¾¶´Ó¶øÏÂÔØÊý¾Ý¿âÅäÖÃÎļþ¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Free-IPA_XXE×¢Èë[CVE-2022-2414][CNNVD-202207-2780]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

FreeIPAÊÇÃâ·ÑµÄ¿ªÔ´Éí·Ý¹ÜÀíϵͳ£¬Æäv11.2.0-beta3Ç°µÄ°æ±¾´æÔÚXMLʵÌå×¢È멶´£¬¹¥»÷ÕßÄܹ»Äܹ»ÀûÓø鶴¶ÁÈ¡Ä¿±ê·þÎñÆ÷Îļþ£¬¶Ë¿Ú̽²âµÈ²Ù×÷

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_±©Á¦²Â½â_HikvisionDVRDS-7204HGHI_±©Á¦²Â½â[CVE-2020-7057][CNNVD-202001-467]

Äþ¾²ÀàÐÍ£º

Çî¾Ù̽²â

ʼþÃèÊö£º

HikvisionDVRDS-7204HGHIV4.0.1build°æ±¾´æÔÚÓû§Ã¶¾Ù©¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ý·µ»Ø°üÅжÏÓû§ÊÇ·ñ´æÔÚ

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SonicWall-SSL-VPN_jarrewrite.sh_ÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

SonicWallSSL-VPN²úÎïÖÐʹÓÃÁ˼«ÎªÀϾɵÄLinuxÄں˺ÍHTTPCGI¿ÉÖ´Ðз¨Ê½£¬¸Ã·¨Ê½ÔÚ´¦ÖÃhttpÇëÇóʱ£¬ÎÞ·¨ÕýÈ·µÄ½âÎöhttpheader¡£¸Ã©¶´µ¼ÖÂÃüÁî×¢È룬Զ³Ì¹¥»÷Õßͨ¹ý×¢ÈëÃüÁî¿ÉÒÔÇáËɵĻñµÃnobodyÓû§È¨Ï޵ĿØÖÆȨÏÞ¡£Í¬Ê±ÓÉÓÚÀϾÉÄں˵ÄÎÊÌâÒÔ¼°ÆäÖдæÔÚ©¶´µÄ¿ÉÖ´Ðз¨Ê½£¬¹¥»÷Õß¿ÉÒÔÇáÒ×µÄÌáÉýȨÏÞ²¢ÍêÈ«½Ó¹Ü¸Ã·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Webmin-Software-Package-Updates_ÃüÁîÖ´ÐÐ[CVE-2022-36446]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

WebminÊÇUnixϵͳ¹ÜÀíWeb½Ó¿Ú£¬Í¨¹ýÈÎÒ»ä¯ÀÀÆ÷¶¼¿ÉÉèÖÃÓû§ÕË»§¡¢Apache¡¢DNS¡¢DNS¡¢Îļþ¹²Ïí¼°ÆäËû¡£Webmin1.998ÒÔÇ°µÄ°æ±¾µÄ/package-updates/update.cgiÔÚÄþ¾²Â©¶´£¬¿ÉÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Ö´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø鶴ִÐÐÈÎÒâOGNL±í´ïʽ¡£Â©¶´´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220823

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

TCP_Ô¶³Ì¿ØÖÆÈí¼þ_·¢ÏÖToDeskʹÓÃ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö£º

¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚʹÓÃToDesk¡£ToDeskÊÇÒ»¿î¶àƽ̨Զ³Ì¿ØÖÆ/Ô¶³ÌЭÖúÈí¼þ£¬Ö÷´òÁ÷³©ÒÔ¼°¸öÈËÃâ·ÑµÄÌصã¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

TCP_ľÂí_PSW.OnlineGames_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£Trojan.PSW.OnlineGamesÊÇÒ»¸öÍøÓεÁºÅľÂí£¬ÍµÈ¡ÍøÓÎDNFµÄÕ˺ÅÃÜÂë·¢Ë͵½ºÚ¿Í·þÎñÆ÷¡£ÍµÈ¡ÍøÓÎDNFµÄÕ˺ÅÃÜÂë¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_µÇ¼ÀÖ³É

Äþ¾²ÀàÐÍ£º

´àÈõ¿ÚÁî

ʼþÃèÊö£º

¼ì²âµ½Ô´IPµØÖ·Ö÷»úÀֳɵǼµ½Ä¿µÄIPµØÖ·Ö÷»úµÄʼþ¡£¸ÃʼþÊÇÕý³£µÄÍøÂçÐÐΪ£¬Ò»°ãûÓÐΣº¦¡£

¸üÐÂʱ¼ä£º

20220823

 

ʼþÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø鶴ִÐÐÈÎÒâOGNL±í´ïʽ¡£Â©¶´´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220823