ÿÖÜÉý¼¶Í¨¸æ-2022-11-15

Ðû²¼Ê±¼ä 2022-11-15
ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_D-LinkDCS-2530LºÍDCS-2670L_¼à¿ØÃô¸ÐÐÅϢй¶[CVE-2020-25078][CNNVD-202009-083]

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚͨ¹ý»á¼ûD-LinkDCS-2530LºÍDCS-2670LµÄ"/config/getuser"»ñÈ¡ÖÎÀíÔ±ÐÅÏ¢¼°ÃÜÂë¡£¡£¡£¡£¡£¡£¡£D-LinkDCS-2530LºÍDCS-2670L¾ùÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÎÞÏßÍøÂçÐźÅÀ©Õ¹Æ÷¡£¡£¡£¡£¡£¡£¡£D-LinkDCS-2530L1.06.01Hotfix֮ǰ°æ±¾ºÍDCS-2670L2.02¼°Ö®Ç°°æ±¾±£´æÐÅϢй¶Îó²î¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËû¿ÉÒÉÐÐΪ_SnakeYAML·´ÐòÁл¯_×Ô½ç˵TAG²ð·ÖÀàÃû

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»ú·¢ËͰüÀ¨Í¨¹ý×Ô½ç˵TAG£¬£¬£¬£¬£¬ £¬£¬£¬²ð·ÖjavaÀàÃûµÄSnakeYAMLÐòÁл¯Êý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÈƹý¼ì²â×°±¸¶ÔSnakeYAML·´ÐòÁл¯Ê¹ÓÃÁ´µÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£SnakeYamlÊÇJavaÓÃÓÚÆÊÎöYaml£¨YetAnotherMarkupLanguage£©ÃûÌÃÊý¾ÝµÄÀà¿â£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖпÉÒÔͨ¹ý×Ô½ç˵tag´¦Öóͷ£Æ÷²ð·ÖjavaÀàÃû

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

TCP_ÆäËû¿ÉÒÉÐÐΪ_java·´ÐòÁл¯_TC_RESETÔàÊý¾Ý

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»ú·¢ËͰüÀ¨´ó×ÚTC_RESETÔàÊý¾ÝµÄÐòÁл¯Êý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÈƹý¼ì²â×°±¸¶Ôjava·´ÐòÁл¯Ê¹ÓÃÁ´µÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£TC_RESETÊÇjavaÐòÁл¯ÃûÌÃÖÐÓÃÓÚÖØÖÃReferenceIDµÄ±êʶ·û£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔͨ¹ý¸Ã±êʶ·û½á¹¹°üÀ¨Éó²ìÔàÊý¾ÝµÄjavaÐòÁл¯Á÷Á¿¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115


ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_AxHostState-BinaryFormatterʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬ £¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬ £¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix_СÓÚ4.4_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃZabbixСÓÚ4.4°æ±¾Öб£´æµÄΪδÊÚȨ»á¼ûÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÔÚδ¾­ÊÚȨµÄÇéÐÎÏ»á¼ûZabbixЧÀÍÆ÷ÉϵÄÊý¾Ý£¬£¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Éó¼Æ_ÉÏ´«war°ü

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«war°ü¡£¡£¡£¡£¡£¡£¡£war°üÊÇJavaWeb³ÌÐò´òµÄ°ü£¬£¬£¬£¬£¬ £¬£¬£¬Ò»¸öwar°ü¿ÉÒÔÃ÷ȷΪÊÇÒ»¸öwebÏîÄ¿£¬£¬£¬£¬£¬ £¬£¬£¬ÄÚÀïÊÇÏîÄ¿µÄËùÓй¤¾ß¡£¡£¡£¡£¡£¡£¡£ÒÔTomcatΪÀý£¬£¬£¬£¬£¬ £¬£¬£¬½«War°ü°²ÅÅÔÚÆä\webapps\Ŀ¼Ï£¬£¬£¬£¬£¬ £¬£¬£¬È»ºóÆô¶¯Tomcat£¬£¬£¬£¬£¬ £¬£¬£¬Õâ¸ö°ü¾Í»á×Ô¶¯½âѹ£¬£¬£¬£¬£¬ £¬£¬£¬°²ÅÅ¡¢Ðû²¼µ½webЧÀÍÖС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Oracle_Weblogic_console_ȨÏÞÈÆ¹ý[CVE-2020-14883][CNNVD-202010-997]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogic10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0ºÍ14.1.1.0.0°æ±¾Öб£´æµÄconsoleȨÏÞÈÆ¹ýÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ·ÇÊÚȨ»á¼ûweblogicconsole£¬£¬£¬£¬£¬ £¬£¬£¬Ö®ºó¿ÉÒÔʹÓÃCVE-2020-14882¿ØÖÆÄ¿µÄϵͳȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£¡£WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬£¬£¬£¬ £¬£¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦ÓóÌÐòЧÀÍÆ÷£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ £¬£¬£¬Ö§³Öй¦Ð§£¬£¬£¬£¬£¬ £¬£¬£¬¿É½µµÍÔËÓª±¾Ç®£¬£¬£¬£¬£¬ £¬£¬£¬Ìá¸ßÐÔÄÜ£¬£¬£¬£¬£¬ £¬£¬£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Weblogic_Îļþ¶ÁÈ¡[CVE-2019-2615]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWeblogic10.3.6.0.0,12.1.3.0.0ºÍ12.2.1.3.0°æ±¾Öб£´æµÄí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶ø»ñȡĿµÄÖ÷»úÃô¸ÐÎļþÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£WeblogicÊÇÏÖÔÚÈ«ÇòÊг¡ÉÏÓ¦ÓÃ×îÆÕ±éµÄJ2EE¹¤¾ßÖ®Ò»£¬£¬£¬£¬£¬ £¬£¬£¬±»³ÆÎªÒµ½ç×î¼ÑµÄÓ¦ÓóÌÐòЧÀÍÆ÷£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÓÃÓÚ¹¹½¨J2EEÓ¦ÓóÌÐò£¬£¬£¬£¬£¬ £¬£¬£¬Ö§³Öй¦Ð§£¬£¬£¬£¬£¬ £¬£¬£¬¿É½µµÍÔËÓª±¾Ç®£¬£¬£¬£¬£¬ £¬£¬£¬Ìá¸ßÐÔÄÜ£¬£¬£¬£¬£¬ £¬£¬£¬ÔöÇ¿¿ÉÀ©Õ¹ÐÔ²¢Ö§³ÖOracleApplications²úÆ·×éºÏ

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Shiro_СÓÚ1.5.3_ȨÏÞÈÆ¹ý[CVE-2020-1957][CNNVD-202003-1579]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃApacheShiroСÓÚ1.5.3ÖÐȨÏÞÈÆ¹ýÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔÈ«ÐĽṹ¶ñÒâµÄURL£¬£¬£¬£¬£¬ £¬£¬£¬Ê¹ÓÃApacheShiroºÍSpringBoot¶ÔURLµÄ´¦Öóͷ£µÄ²î±ð»¯£¬£¬£¬£¬£¬ £¬£¬£¬¿ÉÒÔÈÆ¹ýApacheShiro¶ÔSpringBootÖеÄServletµÄȨÏÞ¿ØÖÆ£¬£¬£¬£¬£¬ £¬£¬£¬ÊµÏÖδÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬£¬£¬£¬ £¬£¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬£¬£¬£¬ £¬£¬£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬣¬£¬£¬£¬ £¬£¬£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬£¬£¬£¬£¬ £¬£¬£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬£¬£¬£¬£¬ £¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221115