ÿÖÜÉý¼¶Í¨¸æ-2021-10-26

Ðû²¼Ê±¼ä 2021-10-27

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁî×¢Èë[CVE-2017-7876][CNNVD-201704-779]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

QNAPSystemsQNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý£¬£¬£¬ £¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£¡£QNAPQTS4.2.6build20170517֮ǰµÄ°æ±¾Öб£´æÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î×¢ÈëÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_VMware_vCenter_Server_ЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î[CVE-2021-21973][CNNVD-202102-1559]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃVMwarevCenterServerЧÀÍÆ÷¶ËÇëÇóαÔìÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚVMwarevCenterServer²å¼þÖжÔÓû§ÌṩµÄÊäÈëÑéÖ¤²»µ±£¬£¬£¬ £¬£¬£¬Î´¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖÆµÄHTTPÇëÇ󣬣¬£¬ £¬£¬£¬ÓÕÆ­Ó¦ÓóÌÐòÏòí§ÒâϵͳÌᳫÇëÇóʵÏÖÄÚÍøÉ¨Ã裬£¬£¬ £¬£¬£¬»ñÈ¡ÄÚÍøÐÅÏ¢£¬£¬£¬ £¬£¬£¬µ¼ÖÂÐÅϢй¶¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jetty_WEB-INF_ÐÅϢй¶Îó²î[CVE-2021-34429]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

EclipseJetty°æ±¾9.4.37-9.4.42¡¢10.0.1-10.0.5ºÍ11.0.1-11.0.5£¬£¬£¬ £¬£¬£¬¿ÉÒÔʹÓÃһЩ±àÂë×Ö·û½á¹¹ÌØÊâµÄURIÀ´»á¼ûWEB-INFĿ¼µÄÄÚÈÝ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211019

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-LinkDSL-2640U&DSL-2540U_ÏÂÁîÖ´ÐÐ[CVE-2018-5371][CNNVD-201801-545]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

D-LinkDSL-2640U×°±¸£¨¹Ì¼þΪIM_1.00ºÍME_1.00£©ºÍDSL-2540U×°±¸£¨¹Ì¼þΪME_1.00£©ÉϵÄdiag_ping.cmdÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýHTTPGETÇëÇóµÄipaddr×Ö¶ÎÖеÄshellÔª×Ö·ûÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Subrion-CMS_´úÂëÖ´ÐÐ[CVE-2018-19422][CNNVD-201811-628]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SubrionCMSÊÇSubrionÍŶӿª·¢µÄÒ»Ì×»ùÓÚPHPµÄÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¡£¡£¡£¡£¸Ãϵͳ¿É±»¼¯³Éµ½ÍøÕ¾£¬£¬£¬ £¬£¬£¬²¢Ö§³Ö¶àÖÖÀ©Õ¹²å¼þµÈ¡£¡£¡£¡£¡£SubrionCMS4.2.1°æ±¾ÖеÄ/panel/uploads±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚ.htaccessÎļþûÓÐեȡ¶ÔphtºÍpharÎļþµÄÖ´ÐвÙ×÷¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú.pht»ò.pharÎļþʹÓøÃÎó²îÖ´ÐÐí§ÒâµÄPHP´úÂë¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_OpenMRS_´úÂëÖ´ÐÐ[CVE-2018-19276][CNNVD-201902-602]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OpenMRSÊÇÃÀ¹úOpenMRS¹«Ë¾µÄÒ»Ì׿ªÔ´µÄµç×Ó²¡Àúϵͳ¡£¡£¡£¡£¡£OpenMRSPlatform2.24.0֮ǰ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Billion_5200W-T_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-18372][CNNVD-201905-077]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Billion5200W-T·ÓÉÆ÷ÔÚʱ¼äÉèÖù¦Ð§Öб£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¸ÃÎó²îλÓÚtools_time.aspÒ³Ãæ£¬£¬£¬ £¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

UDP_DD-WRT_»º³åÇøÒç³öÎó²î[CVE-2021-27137]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

DD-WRTÊÇÒ»¸ö»ùÓÚLinuxµÄÎÞÏß·ÓÉÈí¼þ¡£¡£¡£¡£¡£¸ÃÎó²î£¬£¬£¬ £¬£¬£¬Í¨¹ý»º³åÇøÒç³ö¿ÉÖ´ÐÐí§ÒâÏÂÁ£¬£¬ £¬£¬£¬µ¼ÖÂÖ÷»úÓб»½ÓÊܵÄΣº¦¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Billion_5200W-T_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-18369][CNNVD-201905-073]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Billion5200W-T·ÓÉÆ÷ÔÚÔÚadv_remotelog.aspÎļþÖб£´æÎ´¾­Éí·ÝÑéÖ¤µÄÏÂÁî×¢Èë¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýuiViewSNTPServer²ÎÊý×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_OTRS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2017-16921][CNNVD-201711-917]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÔÚOTRS6.0.xÖÁ6.0.1¡¢OTRS5.0.xÖÁ5.0.24ºÍOTRS4.0.xÖÁ4.0.26ÖУ¬£¬£¬ £¬£¬£¬ÒÔÊðÀíÉí·ÝµÇ¼OTRSµÄ¹¥»÷Õß¿ÉÒÔʹÓÃ±íµ¥²ÎÊý£¨ÓëPGPÏà¹Ø£©²¢ÔÚOTRS»òWebЧÀÍÆ÷Óû§µÄȨÏÞÏÂÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_HPEÖÇÄÜÖÎÀíÖÐÐÄ_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-7184][CNNVD-202010-863]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

HPEIntelligentManagementCenterÊÇÃÀ¹ú»ÝÆÕÆóÒµ¹«Ë¾£¨HewlettPackardEnterprise£¬£¬£¬ £¬£¬£¬HPE£©µÄÒ»Ì×ÍøÂçÖÇÄÜÖÎÀíÖÐÐĽâ¾ö¼Æ»®¡£¡£¡£¡£¡£¸Ã½â¾ö¼Æ»®¿ÉÌṩÕû¸öÍøÂç¹æÄ£µÄ¿ÉÊÓÐÔ£¬£¬£¬ £¬£¬£¬ÊµÏÖ¶Ô×ÊÔ´¡¢Ð§ÀͺÍÓû§µÄÖÜÈ«ÖÎÀí¡£¡£¡£¡£¡£HPEIntelligentManagementCenter(iMC)7.3֮ǰ°æ±¾±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚviewbatchtaskresultdetailfact±í´ïʽÓïÑÔ×¢ÈëÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_FreePBXÇå¾²ÈÆ¹ýÎó²î[CVE-2019-19006][CNNVD-201911-1264]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃFreePBXÇå¾²ÈÆ¹ýÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£¡£FreePBX£¨Ç°³ÆAsteriskManagementPortal£©ÊÇFreePBXÏîÄ¿µÄÒ»Ì×ͨ¹ýGUI£¨»ùÓÚÍøÒ³µÄͼÐλ¯½Ó¿Ú£©ÉèÖÃAsterisk£¨IPµç»°ÏµÍ³£©µÄ¹¤¾ß¡£¡£¡£¡£¡£FreePBX115.0.16.26¼°Ö®Ç°°æ±¾¡¢14.0.13.11¼°Ö®Ç°°æ±¾ºÍ13.0.197.13¼°Ö®Ç°°æ±¾Öб£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµÄ»á¼û¿ØÖÆ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÈÆ¹ýÃÜÂëÉí·ÝÑéÖ¤²¢»á¼ûЧÀ͹¦Ð§¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-Link_DIR-859Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-17621][CNNVD-201912-1224]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃD-Link_DIR-859Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£¡£D-LinkDIR-859×°±¸LAN²ãÖзºÆðδ¾­Éí·ÝÑéÖ¤µÄÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_VMware_NSX_SD-WAN_Edge_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-6961][CNNVD-201805-1140]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃVMware_NSX_SD-WANEdgeµÄÎó²î¾ÙÐй¥»÷£» £»£»£»£» £»VMwareSD-WANEdgeÊÇÒ»¿îÁã½Ó´¥Ê½ÆóÒµ¼¶×°±¸,Äܹ»ÒÔ¾­ÓÉÓÅ»¯µÄ·½·¨Îª×¨ÓС¢¹«¹²»ò»ìÏýÓ¦ÓÃ,ÒÔ¼°ÅÌËãºÍÐéÄ⻯ЧÀÍÌṩÇå¾²ÅþÁ¬¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ZyXEL-CloudCNM-SecuManager_´úÂë×¢Èë[CVE-2020-15348][CNNVD-202006-1754]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZyxelCNMSecuManager3.1.0ºÍ3.1.1°æ±£´æÓ²±àÂëÉñÃØ¡¢Éí·ÝÑé֤ɥʧ¡¢ºóÃźÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£Í¨¹ýdelete_cpes_by_ids¾ÙÐдúÂë×¢Èë¿ÉÖ´ÐÐí§Òâ´úÂ룬£¬£¬ £¬£¬£¬Î£º¦Ö÷»úÇå¾²¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026

 

ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_FCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃFCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£FCKeditorÊÇ¿ªÔ´µÄÍøÒ³±à¼­Æ÷£¬£¬£¬ £¬£¬£¬±»ÖÚ¶à´øÓб༭¹¦Ð§µÄÍøÕ¾»òÕßCMSʹÓᣡ£¡£¡£¡£FCKeditor±£´æFCKeditor_ASP_ÆÊÎöÎó²îÉÏ´«¾ç±¾Ö´ÐÐÎó²î£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓôËÎó²îÉÏ´«í§ÒâÀàÐÍÎļþ£¬£¬£¬ £¬£¬£¬»ñȡĿµÄÍøÕ¾µÄwebshell£¬£¬£¬ £¬£¬£¬½øÒ»²½»ñÈ¡ÍøÕ¾¿ØÖÆÈ¨¡£¡£¡£¡£¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026


 

ÊÂÎñÃû³Æ£º

HTTP_fastjson_1.2.61_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬ £¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬ £¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬ £¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬ £¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬ £¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬ £¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬ £¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211026


ɾ³ýÊÂÎñ


1¡¢HTTP_ͨÓÃ_unicodeÈÆ¹ý

2¡¢SMB_¾Ü¾øÐ§ÀÍ_Winnuke_¹¥»÷[CVE-1999-0153]