ÿÖÜÉý¼¶Í¨¸æ-2022-10-04

Ðû²¼Ê±¼ä 2022-10-04

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_VMware_vCenter_Server_SSRF·þÎñ¶ËÇëÇóαÔì[CVE-2021-21973][CNNVD-202102-1559]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃVMwarevCenterServerδ¶ÔÓû§ÌṩµÄÊäÈëÑéÖ¤µÄ©¶´£¬ÔÚ¡°vcIP¡±½á¹¹¶ñÒâip£¬ÆÛÆ­Ó¦Ó÷¨Ê½ÏòÈÎÒâϵͳÌᳫÇëÇóʵÏÖÄÚÍøÉ¨Ã裬´Ó¶ø»ñÈ¡ÄÚÍøÐÅÏ¢£¬µ¼ÖÂÐÅϢй¶¡£VMwarevCenterServer£¨ÒÔǰ³ÆÎªVMwareVirtualCenter£©£¬¿É¼¯ÖйÜÀíVMwarevSphere»·¾³£¬ÓëÆäËû¹ÜÀíÆ½Ì¨Ïà±È£¬¼«´óµØÌá¸ßÁËIT¹ÜÀíÔ±¶ÔÐéÄâ»·¾³µÄ¿ØÖÆ¡£

¸üÐÂʱ¼ä£º

20221004

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ToTolink_t6_firmware_ÃüÁîÖ´ÐÐ[CVE-2022-38828]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃToTolink_t6_firmwareV4.1.5cu.709_B20210518ÖÐcstecgi.cgi´¦µÄ©¶´£¬½á¹¹¶ñÒâÃüÁî½øÐÐÃüÁî×¢Èë¹¥»÷£¬´Ó¶ø»ñȡĿ±êϵͳȨÏÞ¡£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_RDP_ɨÃè

Äþ¾²ÀàÐÍ£º

Äþ¾²É¨Ãè

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓöÔÄ¿µÄÖ÷»úʹÓÃNMAPͨ¹ýRDPЭÒé»ñÈ¡¼ÆËã»úÐÅÏ¢µÄÐÐΪ¡ £¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004

 

ʼþÃû³Æ£º

TCP_ÍøÂçɨÃè_NMAP¹¤¾ß_RDP_ɨÃè

Äþ¾²ÀàÐÍ£º

Äþ¾²É¨Ãè

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓöÔÄ¿µÄÖ÷»úʹÓÃNMAPͨ¹ýSMBЭÒé»ñÈ¡¼ÆËã»úÐÅÏ¢µÄÐÐΪ¡ £¿ÉÄܻᵼÖÂϵͳй¶Ïà¹ØÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ThinkPHP5.15.2_Ô¶³Ì´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP5Ô¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬¸Ã©¶´ÊÇÓÉÓÚThinkPHP5¿ò¼Üµ×²ã¶Ô¿ØÖÆÆ÷Ãû¹ýÂ˲»ÑÏ£¬´Ó¶øÈù¥»÷Õß¿ÉÒÔͨ¹ýurlµ÷Óõ½ThinkPHP¿ò¼ÜÄÚ²¿µÄÃô¸Ðº¯Êý£¬½ø¶øµ¼ÖÂgetshell©¶´¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ThinkPHPÊÇÒ»¸ö¿ìËÙ¡¢¼æÈݶøÇÒ¼òµ¥µÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£

¸üÐÂʱ¼ä£º

20221004


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jolokia_JNDI_Ô¶³Ì´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃJolokiaµÄJNDI½Ó¿Ú½á¹¹¶ñÒâldapºÍrmiÇëÇ󣬴ӶøÖ´ÐÐÈÎÒâ´úÂë¡£JolokiaÊÇÒ»¸öJMX-HTTPÁ¬½ÓÆ÷£¬¿ÉÒÔÌæ´úJSR-160Á¬½ÓÆ÷¡£

¸üÐÂʱ¼ä£º

20221004

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ThinkPHP5.0.x_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2018-20062][CNNVD-201812-489]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP¿ò¼ÜµÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬ÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£ThinkPHPÊÇÒ»¸öÁ÷ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü

¸üÐÂʱ¼ä£º

20221004

 

ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_Social_Warfare_Plugin_before3.5.3_Îļþ°üÂÞ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWordPressµÄSocial_Warfare²å¼þ½øÐÐÔ¶³Ì´úÂëÖ´ÐУ¬¸Ã²å¼þûÓжԴ«Èë²ÎÊý½øÐÐÑϸñ¿ØÖÆÒÔ¼°¹ýÂË£¬µ¼Ö¹¥»÷Õ߿ɽṹ¶ñÒâpayload£¬ÎÞÐèºǫ́ȨÏÞ£¬Ö±½ÓÔì³ÉÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£social-warfareÊÇÒ»¿îWordPressÉç½»·ÖÏí°´Å¥²å¼þ¡£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON_databind_caucho_Ô¶³Ì´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÄ¿µÄÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬Í¨¹ýcom.caucho.config.types.ResourceRefÀà½á¹¹¶ñÒâjava´úÂë¡£jackson-databindÊÇÁ¥ÊôFasterXMLÏîÄ¿×éϵÄJSON´¦Öÿâ¡£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_JACKSON_Shiro_Ô¶³Ì´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÄ¿µÄÖ÷»úÉÏJACKSONµÄºÚÃûµ¥¾ÖÏÞ£¬Í¨¹ýshiro-coreÀà´¥·¢JNDIÔ¶³ÌÀà¼ÓÔØ²Ù×÷¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßÓÐÊý¾Ý°ó¶¨¹¦Ð§µÄºËÐÄ×é¼þÖ®Ò»¡£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_WebLogic_´úÂëÖ´ÐÐ[CVE-2022-21350]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWeblogicÖеÄOracleFusionMiddleware£¨×é¼þ£ºCore£©ÖеÄ©¶´½á¹¹¶ñÒâ·´ÐòÁдúÂëͨ¹ýT3·ÃÎÊÍøÂçÀ´½øÐй¥»÷£»WeblogicÊÇĿǰȫÇòÊг¡ÉÏÓ¦ÓÃ×î¹ã·ºµÄJ2EE¹¤¾ßÖ®Ò»£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦Ó÷¨Ê½·þÎñÆ÷£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦Ó÷¨Ê½£¬Ö§³Öй¦Ð§£¬¿É½µµÍÔËÓª³É±¾£¬Ìá¸ßÐÔÄÜ£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÎï×éºÏ¡£T3ЭÒéÊÇÓÃÓÚWeblogic·þÎñÆ÷ºÍÆäËûJavaApplicationÖ®¼ä´«ÊäÐÅÏ¢µÄЭÒ飬ÊÇʵÏÖRMIÔ¶³Ì¹ý³Ìµ÷ÓõÄרÓÐЭÒ飬ÆäÔÊÐí¿Í»§¶Ë½øÐÐJNDIµ÷Óá£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

HTTP_ÍøÂçɨÃè_Ìì¾µ6.0ɨÃèÆ÷

Äþ¾²ÀàÐÍ£º

Äþ¾²É¨Ãè

ʼþÃèÊö£º

¼ì²âµ½Ô´IPµØÖ·µÄÖ÷»úÕýÔÚʹÓÃÌì¾µ6.0ɨÃ蹤¾ß¶ÔÄ¿µÄIPµØÖ·½øÐЩ¶´É¨Ãè¡£Ìì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳÊǶ¶È¦Îª¶Ä¶øÉú¹«Ë¾×ÔÖ÷Ñз¢µÄ»ùÓÚÍøÂçµÄÄþ¾²ÐÔÄÜÆÀ¹À·ÖÎöϵͳ£¬¿ÉÒÔ¶ÔÍøÂçÖеÄÖÖÖÖϵͳ¡¢É豸ºÍÊý¾Ý¿â½øÐЩ¶´É¨Ã裬¶ÔÍøÂç½øÐÐÓÐЧµÄÆÀ¹À£¬²¢Ìá³ö½¨ÉèÐԵĽâ¾ö·½°¸¡ £¿ÉÄܻᵼÖÂÄ¿µÄϵͳй¶ijЩÃô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

HTTP_×¢Èë¹¥»÷_WebLogic_Blind_XXE×¢Èë[CVE-2019-2647]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWebLogic_Blind_XXE×¢Èë©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£WebLogic_Blind_XXE×¢Èë©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϽ«payload·â×°ÔÚT3ЭÒéÖУ¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload½øÐз´ÐòÁл¯£¬´Ó¶øÊµÏÖ¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlindXXE¹¥»÷£¬¶ÁȡĿ±êϵͳÎļþ¡£

¸üÐÂʱ¼ä£º

20221004

 

ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Adobe_Coldfusion_JNBridge_listener_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2019-7839][CNNVD-201906-514]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÕýÔÚÀûÓÃAdobeColdfusionµÄJNBridge×é¼þµÄ©¶´½á¹¹¶ñÒâjava´úÂ룬´Ó¶øÖ´ÐÐÈÎÒâÃüÁî¡£AdobeColdFusionÊÇÒ»¸öÉÌÓõĿìËÙ¿ª·¢Æ½Ì¨¡£Ëü¿ÉÒÔ×÷Ϊһ¸ö¿ª·¢Æ½Ì¨Ê¹Óã¬Ò²¿ÉÒÔÌṩFlashÔ¶³Ì·þÎñ»òÕß×÷ΪAdobeFlexÓ¦Óõĺǫ́·þÎñÆ÷¡£ÓÉÓÚJNBridge×é¼þ´æÔÚȱÏÝ£¬¶øColdFusionĬÈÏ¿ªÆôJNBridge×é¼þ£¬¿ÉÄܵ¼Ö´úÂëÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Cacti_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-8813][CNNVD-202002-1075]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚͨ¹ýÔÚCacti1.2.8¼°Ö®Ç°µÄ°æ±¾µÄ·Ã¿ÍÒ³Ãæ¡°graph_realtime.php¡±´¦Î´¶ÔCookie´¦µÄÊäÈë½øÐÐÑéÖ¤µÄ©¶´£¬½á¹¹¶ñÒâ´úÂë´Ó¶øÖ´ÐÐÔ¶³ÌÃüÁî¡££¬CactiÊÇÒ»Ì×»ùÓÚPHP,MySQL,SNMP¼°RRDTool¿ª·¢µÄÍøÂçÁ÷Á¿¼à²âͼÐηÖÎö¹¤¾ß¡£Ëüͨ¹ýsnmpgetÀ´»ñÈ¡Êý¾Ý£¬Ê¹ÓÃRRDtool»æ»­Í¼ÐΣ¬¶øÇÒÍêÈ«¿ÉÒÔ²»ÐèÒªÁ˽âRRDtoolÅÓ´óµÄ²ÎÊý¡£

¸üÐÂʱ¼ä£º

20221004


 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jellyfin_SSRF_·þÎñ¶ËÇëÇóαÔì[CVE-2021-29490]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´Ö÷»úipÕýÔÚÀûÓÃJellyfin¼°10.7.3֮ǰµÄSSRF©¶´£¬½á¹¹¶ñÒâÇëÇó¸Ã©¶´Ì½²âÄÚÍøÐÅÏ¢¡£JellyfinÊÇÒ»¸öÃâ·ÑµÄÈí¼þýÌåϵͳ¡£

¸üÐÂʱ¼ä£º

20221004

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_weblogic_·þÎñ¶ËÇëÇóαÔì[CVE-2014-4210]

Äþ¾²ÀàÐÍ£º

Äþ¾²É¨Ãè

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃweblogic·þÎñ¶ËÇëÇóαÔì©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£OracleWebLogicServerÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚÔÆ»·¾³ºÍ´«Í³»·¾³µÄÓ¦Ó÷þÎñÆ÷£¬ËüÌṩÁËÒ»¸öÏÖ´úÇáÐÍ¿ª·¢Æ½Ì¨£¬Ö§³ÖÓ¦Óôӿª·¢µ½Éú²úµÄÕû¸öÉúÃüÖÜÆÚ¹ÜÀí£¬²¢¼ò»¯ÁËÓ¦ÓõIJ¿ÊðºÍ¹ÜÀí¡£OracleFusionMiddleware10.0.2.0ºÍ10.3.6.0°æ±¾µÄOracleWebLogicServer×é¼þÖеÄWLS-WebServices×Ó×é¼þ´æÔÚÄþ¾²Â©¶´¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓøÃ©¶´¶ÁÈ¡Êý¾Ý£¬Ó°ÏìÊý¾ÝµÄ±£ÃÜÐÔ¡£»ñÈ¡ÄÚÍøÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20221004