ÿÖÜÉý¼¶Í¨¸æ-2021-09-21

Ðû²¼Ê±¼ä 2021-09-22

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÎļþ»á¼û_³£¼ûÃüÃû

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé»á¼ûÄ¿µÄIPÖ÷»úÉϵĿÉÒÉÎļþµÄÐÐΪ¡£¡£¡£´ËÊÂÎñ½ö¹©ÐÅÏ¢²Î¿¼£¬£¬£¬²»´ú±íÕæÊµ¹¥»÷¡£¡£¡£ÐèҪȷÈÏ»á¼ûµÄÎļþÔÚÄ¿µÄIPÖ÷»úÉÏÊÇ·ñÕæÊµ±£´æ¡£¡£¡£ÇÒÐèҪȷÈÏÎļþÄÚÈÝÊÇ·ñΪ¶ñÒâÄÚÈÝ¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_TP-Link_TL-WR940N_´úÂëÖ´ÐÐ[CVE-2019-6989][CNNVD-201904-442]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TP-LinkTL-WR940NºÍTP-LinkTL-WR941ND¶¼ÊÇÖйúÆÕÁª£¨TP-Link£©µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£¡£TP-LINKTL-WR940NºÍTL-WR941NDÖб£´æ»º³åÇø¹ýʧÎó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úÆ·ÔÚÄÚ´æÉÏÖ´ÐвÙ×÷ʱ£¬£¬£¬Î´×¼È·ÑéÖ¤Êý¾Ý½çÏߣ¬£¬£¬µ¼ÖÂÏò¹ØÁªµÄÆäËûÄÚ´æÎ»ÖÃÉÏÖ´ÐÐÁ˹ýʧµÄ¶Áд²Ù×÷¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îµ¼Ö»º³åÇøÒç³ö»ò¶ÑÒç³öµÈ¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921

 


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Gh0st_Shine_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø³ÌÐò£¬£¬£¬¹¦Ð§Ê®·Öǿʢ¡£¡£¡£¾ßÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢½¨É衢ɾ³ý£©¡¢Àú³ÌÖÎÀí¡¢ÏµÍ³Ð§ÀÍ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢Éó²éÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921

 


ÊÂÎñÃû³Æ£º

HTTP_Ç徲ɨÃè_ɨÃèÆ÷nessus

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

NessusÊÇÊ®·ÖǿʢµÄÎó²îɨÃèÆ÷£¬£¬£¬¸Ã¹¤¾ß°üÀ¨×îеÄÎó²îÊý¾Ý¿â£¬£¬£¬¼ì²âËÙÂʿ죬£¬£¬×¼È·ÐԸߣ¬£¬£¬ÊÇÉøÍ¸²âÊÔÖ÷Òª¹¤¾ßÖ®Ò»¡£¡£¡£¸Ã¸æ¾¯ËµÃ÷¼ì²âµ½nessusɨÃèÆ÷ɨÃèÁ÷Á¿¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Optergy-Proton-Enterprise_ÏÂÁî×¢ÈëÎó²î[CVE-2019-7276][CNNVD-201906-284]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OptergyProtonEnterpriseÊÇÃÀ¹úOptergy¹«Ë¾µÄÒ»ÌׯóÒµÐÞ½¨ÖÎÀíϵͳ¡£¡£¡£OptergyProtonEnterprise2.3.0a¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ±½Óµ¼º½µ½Î´±»¼Í¼µÄºóÞ籾£¬£¬£¬»ñÈ¡ËùÓеÄϵͳ»á¼ûȨÏÞ£¬£¬£¬½ø¶øÒÔ×î¸ßȨÏÞÖ´ÐдúÂë¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_rConfig_System_ajaxArchiveFiles.phpÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-19509][CNNVD-202001-144]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃrConfig_System_ajaxArchiveFiles.phpÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£rConfig3.9.3Öз¢Ã÷ÁËÒ»¸öÎÊÌâ¡£¡£¡£Ô¶³ÌÈÏÖ¤Óû§¿ÉÒÔͨ¹ýÏòajaxArchiveFiles.php·¢ËÍGETÇëÇóÖ±½ÓÖ´ÐÐϵͳÏÂÁ£¬£¬ÓÉÓÚpath²ÎÊýûÓйýÂ˾Íת´ï¸øexecº¯Êý£¬£¬£¬Õâ»áµ¼ÖÂÏÂÁîÖ´ÐС£¡£¡£

¸üÐÂʱ¼ä£º

20210921

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-Link-DIR-818LW&DIR-822_ÏÂÁî×¢Èë[CVE-2018-19986][CNNVD-201905-305]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

D-LinkDIR-822ºÍD-LinkDIR-818LW¶¼ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷¡£¡£¡£D-LinkDIR-818LWRev.A2.05.B03ºÍDIR-822B1202KRb06Öеġ®RemotePort¡¯²ÎÊý±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÏÂÁîµÈ¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨²Ù×÷ϵͳÏÂÁî¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Ãô¸ÐÎļþ»á¼û

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÄ¿µÄipÖ÷»úÖпÉÄÜ̻¶ÔÚÍâµÄÃô¸ÐÎļþ¡£¡£¡£

¸üÐÂʱ¼ä£º

20210914

 


ÊÂÎñÃû³Æ£º

TCP_Java¶¯Ì¬Å²ÓÃ_java.lang.ProcessBuilder_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£ÔÚJavaÖУ¬£¬£¬³ÌÐò¿ª·¢Ö°Ô±Í¨³£»£»£»£»£»áͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨Ö´ÐÐÍⲿµÄShellÏÂÁî¡£¡£¡£ProcessBuilderÊÇjava5.0ÒýÈëµÄ£¬£¬£¬start()ÒªÁì·µ»ØProcessµÄÒ»¸öʵÀý¡£¡£¡£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬£¬£¬ÈôÊÇ´¦Öóͷ£ÍâÊÖÏÂÁîÖ´ÐÐʱ£¬£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐÓõĹýÂË£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎó²îÔ¶³Ì×¢ÈëÏÂÁî»ò´úÂë²¢Ö´ÐС£¡£¡£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÒ»¾­±»Åû¶³ö±£´æJavaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õßͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½·¨ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬½øÒ»²½ÍêÈ«¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

¸üÐÂʱ¼ä£º

20210914

 

 

ÊÂÎñÃû³Æ£º

TCP_Java¾²Ì¬Å²ÓÃ_java.lang.Runtime_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´Ä¿µÄIPÕýÔÚʹÓÃJava¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨¾ÙÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£ÔÚJavaÖУ¬£¬£¬³ÌÐò¿ª·¢Ö°Ô±Í¨³£»£»£»£»£»áͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨Ö´ÐÐÍⲿµÄShellÏÂÁî¡£¡£¡£RuntimeÀàÊÇJava³ÌÐòµÄÔËÐÐʱÇéÐΣ¬£¬£¬¿ª·¢Õß¿ÉÒÔͨ¹ýgetRuntime()ÒªÁì»ñȡĿ½ñRuntimeÔËÐÐʱ¹¤¾ßµÄÒýÓᣡ£¡£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬£¬£¬ÈôÊÇ´¦Öóͷ£ÍâÊÖÏÂÁîÖ´ÐÐʱ£¬£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐÓõĹýÂË£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâ¸öÎó²îÔ¶³Ì×¢ÈëÏÂÁî»ò´úÂë²¢Ö´ÐС£¡£¡£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÒ»¾­±»Åû¶³ö±£´æJavaÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õßͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½·¨ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬£¬½øÒ»²½ÍêÈ«¿ØÖÆÄ¿µÄЧÀÍÆ÷¡£¡£¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921

 

 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_ÓÃÓÑNC_ÀúÊ·Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP¿ÉÄÜÕýÔÚʹÓÃÓÃÓÑNCµÄÎó²î¾ÙÐй¥»÷£»£»£»£»£»¹¥»÷Õßͨ¹ý½á¹¹ÓÃÓÑÌØ¶¨µÄ·ÓÉʵÏÖ´úÂëÖ´ÐС¢Îļþ¶ÁÈ¡µÈ²Ù×÷£»£»£»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬£¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳ¡£¡£¡£

¸üÐÂʱ¼ä£º

20210921