ÿÖÜÉý¼¶Í¨¸æ-2021-11-30
Ðû²¼Ê±¼ä 2021-12-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_QNAP-QTS_´úÂëÖ´ÐÐ[CVE-2017-6361][CNNVD-201702-940] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬£¬£¬£¬£¬£¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁîÖ´ÐÐ[CVE-2017-6360][CNNVD-201702-941] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬£¬£¬£¬£¬£¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬£¬£¬»ñÈ¡ÖÎÀíԱȨÏÞºÍÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁîÖ´ÐÐ[CVE-2017-6359][CNNVD-201702-942] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬£¬£¬£¬£¬£¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡ÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | TCP_Çå¾²Îó²î_Hadoop_Yarn_RPCδÊÚȨ»á¼ûÎó²î |
Çå¾²ÀàÐÍ£º | ·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃHadoopYarnµÄÎó²î¾ÙÐÐδÊÚȨ»á¼û£»£»£»£»¹ØÓÚ8032̻¶ÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬£¬£¬£¬£¬£¬£¬£¬±àдӦÓóÌÐòŲÓÃyarnClient.getApplications()¼´¿ÉÉó²éËùÓÐÓ¦ÓÃÐÅÏ¢£»£»£»£»Hadoop×÷Ϊһ¸öÂþÑÜʽÅÌËãÓ¦Óÿò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬ÖÖÀ๦Ч·±¶à£¬£¬£¬£¬£¬£¬£¬£¬¶øHadoopYarn×÷ΪÆä½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Apache_CouchDB_JSON_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-12636][CNNVD-201711-486] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃApacheCouchDBJSONÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£¡£¡£¡£¡£ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬×¨×¢ÓÚÒ×ÓÃÐԺͳÉΪ"Íêȫӵ±§webµÄÊý¾Ý¿â"¡£¡£¡£¡£¡£¡£¡£¡£CouchDB»áĬÈÏ»áÔÚ5984¶Ë¿Ú¿ª·ÅRestfulµÄAPI½Ó¿Ú£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÊý¾Ý¿âµÄÖÎÀí¹¦Ð§¡£¡£¡£¡£¡£¡£¡£¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌ㬣¬£¬£¬£¬£¬£¬£¬JavaScript×÷ΪÅÌÎÊÓïÑÔ£¬£¬£¬£¬£¬£¬£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¡£CouchDB½ÓÄÉ»ùÓÚErlangµÄJSONÆÊÎöÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Óë»ùÓÚJavaScriptµÄJSONÆÊÎöÆ÷²î±ð£¬£¬£¬£¬£¬£¬£¬£¬CouchDB¿ÉÒÔÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇɫ֨¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ°üÀ¨ÌåÏÖÖÎÀíÓû§µÄ_admin½ÇÉ«¡£¡£¡£¡£¡£¡£¡£¡£¶ñÒâ¹¥»÷ÕßʹÓÃÕâÒ»¹¦Ð§²¢Á¬ÏµCVE-2017-12636Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹ·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâshellÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Netgear_Nighthawk_R7000δÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-31802] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃNetgea·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£¡£¡£¡£¡£ÔÚNETGEARR7000Éϱ£´æÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Çå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£¡£Îó²îʹÓÃÀֳɺ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Primefaces_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-1000486][CNNVD-201801-112] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | PrimeFacesÊÇÒ»¸ö¿ªÔ´Óû§½çÃæ(UI)×é¼þ¿â£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ»ùÓÚJavaServerFacesµÄÓ¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÍÁ¶úÆä¹«Ë¾PrimeTekInformatics½¨Éè¡£¡£¡£¡£¡£¡£¡£¡£Primefaces5.x±£´æÈõ¼ÓÃÜÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_D-Link_DWL-2600AP_²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î[CVE-2019-20499/CVE-2019-20500/CVE-2019-20501][CNNVD-202003-201/CNNVD-202003-205/CNNVD-202003-204] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | D-LinkDWL-2600APÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß½ÓÈëµã×°±¸¡£¡£¡£¡£¡£¡£¡£¡£D-LinkDWL-2600AP4.2.0.15RevA°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽèÖúÉúÑÄÉèÖù¦Ð§Ê¹ÓøÃÎó²îÖ´ÐÐí§ÒâµÄ²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Terramaster_TOS_ÏÂÁî×¢ÈëÎó²î[CVE-2020-35665] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×ÓÊÖÒÕ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬£¬£¬£¬£¬£¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NASЧÀÍÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýÔÚÊÂÎñ²ÎÊýÖаüÀ¨makecvs.php×¢Èë²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_SQL_Server_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0618][CNNVD-202002-496] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS)£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÏÖÔÚÌìÏÂÉÏÆÕ±éʹÓõÄÊý¾Ý¿âÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹÓôËÎó²îÔÚ±¨±íЧÀÍÆ÷ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_´úÂëÖ´ÐÐ_ÆïÊ¿CMSÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-35339][CNNVD-202102-1295] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÆïÊ¿CMSµÄ¡°ÍøÕ¾ÓòÃû¡±¶ÔÓ¦²ÎÊý¾ÙÐдúÂëÖ´ÐвÙ×÷£»£»£»£»ÆïÊ¿È˲ÅϵͳÊÇÒ»Ïî»ùÓÚPHPMYSQLΪ½¹µã¿ª·¢µÄÒ»Ì×Ãâ·Ñ¿ªÔ´×¨ÒµÈ˲ÅÕÐÆ¸ÏµÍ³¡£¡£¡£¡£¡£¡£¡£¡£ÎªÐ¡ÎÒ˽¼ÒÇóÖ°ºÍÆóÒµÕÐÆ¸ÌṩÐÅÏ¢»¯½â¾ö¼Æ»®,ÆïÊ¿È˲Åϵͳ¾ß±¸Ö´ÐÐЧÂʸߡ¢Ä£°åÇл»×ÔÓÉ¡¢ºǫ́ÖÎÀí¹¦Ð§ÎÞа¡¢Ä£¿£¿£¿£¿£¿£¿é¹¦Ð§Ç¿Ê¢µÈÌØµã¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_XStream_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-26217][CNNVD-202011-1441] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | Xstream½â×éʱ´¦Öóͷ£µÄÁ÷°üÀ¨ÀàÐÍÐÅÏ¢ÒÔÖØÐ½¨ÉèÒÔǰ±àдµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£XStreamÒò´Ë»ùÓÚÕâЩÀàÐÍÐÅÏ¢½¨ÉèÐÂʵÀý¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô¦Öóͷ£¹ýµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢Èë¿ÉÒÔÖ´ÐÐí§ÒâshellÏÂÁîµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÏÂÁîÎó²î |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ÷ÈħӰϷ³ÌÐò(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉÆµÄǿʢÊÓÆµÓ°Ï·ÏµÍ³¡£¡£¡£¡£¡£¡£¡£¡£ÍêÉÆÖ§³ÖÖÚ¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬£¬£¬£¬£¬£¬£¬£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÖ÷ÒªµÄ±¬·¢Ôµ¹ÊÔÓÉÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£¡£¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20211130 |


¾©¹«Íø°²±¸11010802024551ºÅ