ÿÖÜÉý¼¶Í¨¸æ-2022-08-16

Ðû²¼Ê±¼ä 2022-08-16

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_×¢Èë¹¥»÷_WebLogic_WsrmSequenceContext_XXE×¢Èë[CVE-2019-2650][CNNVD-201904-726]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_WebLogic_WsrmSequenceContext_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£ ¡£¡£HTTP_WebLogic_WsrmSequenceContext_XXE×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬£¬£¬£¬£¬£¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlindXXE¹¥»÷¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816


 

ÊÂÎñÃû³Æ£º

TCP_×¢Èë¹¥»÷_WebLogic_EJBTaglibDescriptor_XXE×¢Èë[CVE-2019-2888][CNNVD-201904-706]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_WebLogic_EJBTaglibDescriptor_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£ ¡£¡£HTTP_WebLogic_EJBTaglibDescriptor_XXE×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬£¬£¬£¬£¬£¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³Ì·´ÐòÁл¯XXE¹¥»÷¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Joomla_B2jcontact_2.1.17_ÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

B2J_contactÊÇ×îÊܽӴýµÄÀ©Õ¹CodextrousÖ®Ò»£¬£¬£¬£¬£¬£¬ÓÃÓÚ½¨ÉèÁªÏµ±íµ¥¡£¡£¡£ ¡£¡£ÕâÖÖ¸ïÃüÐԵĶ๦ЧJoomla_contact×é¼þÊdz¬µÈÒ×ÓÚ×°Ö㬣¬£¬£¬£¬£¬Í¨¹ýÆä¾«Á·µÄÉè¼ÆºÍÓû§ÓѺõĺó¶ËΪÄú´øÀ´×îÖÕµÄÓû§ÌåÑé¡£¡£¡£ ¡£¡£ÔÚÆä×é¼þ(2.1.17°æ±¾)Öб£´æí§ÒâÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß»áʹÓôËÎó²î£¬£¬£¬£¬£¬£¬ÉÏ´«¶ñÒâ´úÂë¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816


 

ÊÂÎñÃû³Æ£º

TCP_Ô¶³Ì¿ØÖÆÈí¼þ_·¢Ã÷ToDeskʹÓÃ

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚʹÓÃToDesk¡£¡£¡£ ¡£¡£ToDeskÊÇÒ»¿î¶àƽ̨Զ³Ì¿ØÖÆ/Ô¶³ÌЭÖúÈí¼þ£¬£¬£¬£¬£¬£¬Ö÷´òÁ÷ͨÒÔ¼°Ð¡ÎÒ˽¼ÒÃâ·ÑµÄÌØµã¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÒÚÈüͨµç×ÓÎĵµÖÎÀíϵͳ_dataimport_ÏÂÁîÖ´ÐÐ[CNVD-2021-43589]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÒÚÈüͨµç×ÓÎĵµÇå¾²ÖÎÀíϵͳ£¨¼ò³ÆCDG£©ÊÇÒ»¿îµç×ÓÎĵµÇå¾²¼ÓÃÜÈí¼þ£¬£¬£¬£¬£¬£¬¸ÃϵͳʹÓÃÇý¶¯²ã͸Ã÷¼ÓÃÜÊÖÒÕ£¬£¬£¬£¬£¬£¬Í¨¹ý¶Ôµç×ÓÎĵµµÄ¼ÓÃܱ£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬±ÜÃâÄÚ²¿Ô±¹¤Ð¹ÃܺÍÍⲿְԱ²»·¨ÇÔÈ¡ÆóÒµ½¹µãÖ÷ÒªÊý¾Ý×ʲú¡£¡£¡£ ¡£¡£ÒÚÈüͨµç×ÓÎĵµÖÎÀíϵͳ±£´æÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£ ¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡ÍøÕ¾Ð§ÀÍÆ÷¿ØÖÆÈ¨¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Oracle-Weblogic-console_ȨÏÞÈÆ¹ý[CVE-2020-14883][CNNVD-202010-997]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogicconsoleȨÏÞÈÆ¹ýÎó²î£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔ·ÇÊÚȨ»á¼ûweblogicconsole£¬£¬£¬£¬£¬£¬Ö®ºó¿ÉÒÔʹÓÃCVE-2020-14882¿ØÖÆÄ¿µÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20220816


 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Druid_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

DruidÊǰ¢Àï°Í°ÍÊý¾Ý¿âÊÂÒµ²¿³öÆ·£¬£¬£¬£¬£¬£¬Îª¼à¿Ø¶øÉúµÄÊý¾Ý¿âÅþÁ¬³Ø£¬£¬£¬£¬£¬£¬DruidÌṩµÄ¼à¿Ø¹¦Ð§£¬£¬£¬£¬£¬£¬¼à¿ØSQLµÄÖ´ÐÐʱ¼ä¡¢¼à¿ØWebURIµÄÇëÇó¡¢Session¼à¿Ø£¬£¬£¬£¬£¬£¬µ±¿ª·¢ÕßÉèÖò»µ±ÊÔ´Í¿ÉÄÜÔì³ÉδÊÚȨ»á¼ûÎó²î¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816

 

ÊÂÎñÃû³Æ£º

TCP_×¢Èë¹¥»÷_WebLogic_ForeignRecoveryContext_XXE×¢Èë[CVE-2019-2648]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_WebLogic_ForeignRecoveryContext_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£ ¡£¡£HTTP_WebLogic_ForeignRecoveryContext_XXE×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬£¬£¬£¬£¬£¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlindXXE¹¥»÷¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£ ¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£ ¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£

¸üÐÂʱ¼ä£º

20220816