ÐÛÂõÔÆÐ§ÀÍÆ÷ÄÚÖÃÓ²±àÂëÕË»§Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-10-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17919£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.1£¬ £¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


º¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾XMeye P2PÔÆÐ§ÀÍÆ÷
ËùÓÐͨ¹ýº¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾´ú¹¤µÄ»ùÓÚXMeye P2PÔÆÐ§ÀÍÆ÷×°±¸


Îó²î¸ÅÊö


XMeye P2PÔÆÐ§ÀÍÆ÷ÊÇÒ»ÖÖÓÃÓÚNVR/DVR×°±¸ÖÎÀíµÄ×é¼þ£¬ £¬£¬£¬£¬Óɺ¼ÖÝÐÛÂõ¹«Ë¾Éú²ú¡£¡£¡£¡£¡£´Ë×é¼þ±»·¢Ã÷±£´æÄÚÖÃÓ²±àÂëµÄÕ˺Å£¬ £¬£¬£¬£¬¿É±»Ô¶³Ìͨ¹ýWeb½çÃæµÇ¼´Ó¶øÊµÏÖ·ÇÊÚȨµÄ×°±¸ÖÎÀí£¬ £¬£¬£¬£¬ËùÓÐʹÓôË×é¼þµÄ×°±¸¾ù´ËÇå¾²ÎÊÌâµÄÓ°Ïì¡£¡£¡£¡£¡£Í¬Ê±×°±¸»¹±£´æÏÔ×ŵÄĿ¼±éÀúÎó²î£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ¶ÁȡϵͳÖеÄí§ÒâÎļþ£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎÊÌâ½øÒ»²½¿ØÖÆÏµÍ³»ñȡԶ³ÌÏÂÁîÖ´ÐеÄÄÜÁ¦¡£¡£¡£¡£¡£

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÖйúµØÇøÖÐÁÉÄþʡʹÓÃÓÃÊýÄ¿×î¶à£¬ £¬£¬£¬£¬¹²ÓÐ4582̨£»£» £»£»£» £»£»¹ã¶«Ê¡µÚ¶þ£¬ £¬£¬£¬£¬¹²ÓÐ1838̨£¬ £¬£¬£¬£¬É½¶«Ê¡µÚÈý£¬ £¬£¬£¬£¬¹²ÓÐ1566̨£¬ £¬£¬£¬£¬±±¾©ÊеÚËÄ£¬ £¬£¬£¬£¬¹²ÓÐ1492̨£¬ £¬£¬£¬£¬½­ËÕÊ¡µÚÎ壬 £¬£¬£¬£¬¹²ÓÐ1232̨¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP


1¡¢Í¨¹ýWebÖÎÀí½çÃæµÇ¼ÄÚÖÃÓ²±àÂëÕ˺Å
ͨ¹ýä¯ÀÀÆ÷Ö±½Ó»á¼ûurl£¬ £¬£¬£¬£¬Ê¹ÓÃÓ²±àÂëÕË»§¼´¿ÉÖ±½ÓµÇ¼ÊÓÆµ¼à¿Ø½çÃæ¡£¡£¡£¡£¡£Ó²±àÂëÕË»§¼°¿ÚÁîΪ£ºdefault/¿Õ¿ÚÁî»òdefault/tluafed

ÈçÏÂÑÝʾ£º


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


µÇ¼½øÈëºóµÄÖÎÀíÒ³Ãæ£º


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


2¡¢ Web ServeĿ¼±éÀúÎó²î
XMeye P2PÔÆÐ§ÀÍÆ÷Web Server×é¼þȨÏÞÉèÖò»µ±£¬ £¬£¬£¬£¬µ¼Ö¿ÉÒÔ±éÀúĿ¼¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£¡£¡£ÒÔÏÂÒÔʵÑé»á¼û/../../../../../procΪÀý¡£¡£¡£¡£¡£


ÈçÏÂͼ£º

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÐÞ¸´½¨Òé


×Ô²éÒªÁ죺
Éó²éXMeye P2PÔÆÐ§ÀÍÆ÷×°±¸ÊÇ·ñ¿ªÆôWebÖÎÀí£¬ £¬£¬£¬£¬²¢Ê¹ÓÃÄÚÖÃÕË»§ÔÚWebÖÎÀí½çÃæÊµÑéµÇ¼¡£¡£¡£¡£¡£ÈôÉϰ¶Àֳɣ¬ £¬£¬£¬£¬ÔòÎó²î±£´æ¡£¡£¡£¡£¡£

Éý¼¶²¹¶¡£¡£¡£¡£¡£º
º¼ÖÝÐÛÂõÏÖÔÚ²¢Î´¾Í´ËÎó²îÐû²¼Èκβ¹¶¡£¬ £¬£¬£¬£¬Ïà¹ØÊÜÓ°ÏìÓû§ÇëÁªÏµº¼ÖÝÐÛÂõ¿Æ¼¼¼°Ïà¹Ø³§ÉÌ»ñȡ֧³Ö¡£¡£¡£¡£¡£

ÔÝʱ´¦Öóͷ£²½·¥£º
1¡¢Ê¹Óð×Ãûµ¥·½·¨ÏÞÖÆ¿É»á¼ûWEBÖÎÀíÆ½Ì¨µÄȪԴIP»ò¹Ø±ÕWEBÖÎÀíÆ½Ì¨¡£¡£¡£¡£¡£
2¡¢ÍâµØÍ¨¹ý´®¿ÚÐÞ¸ÄÄÚÖõÄrootÕË»§¿ÚÁî¡£¡£¡£¡£¡£

²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06
http://www.xiongmaitech.com/