ÿÖÜÉý¼¶Í¨¸æ-2022-11-01

Ðû²¼Ê±¼ä 2022-11-01
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_drag-and-drop-multiple-file-uploader_ÎļþÉÏ´«[CVE-2020-12800][CNNVD-202006-519]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWordPressdraganddropmultiplefileuploader²å¼þ1.3.3.3֮ǰ°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î£¬ £¬£¬£¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£DragandDropMultipleFileUploaderÊÇContactForm7µÄÒ»¸ö¼òÆÓ¡¢Ö±½ÓµÄWordPress²å¼þÀ©Õ¹£¬ £¬£¬£¬ËüÔÊÐíÓû§Ê¹ÓÃÍϷŹ¦Ð§»òWeb±íµ¥µÄͨÓÃä¯ÀÀÎļþÉÏ´«¶à¸öÎļþ¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_vTiger_CRM_ÎļþÉÏ´«[CVE-2013-3591][CNNVD-201310-746]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃvTigerCRM5.3.0ÒÔ¼°5.4.0°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î£¬ £¬£¬£¬´Ó¶øÔÚÉϰ¶ºó»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£VtigerCRMÊÇÃÀ¹úVtiger¹«Ë¾µÄÒ»Ì×»ùÓÚSugarCRM¿ª·¢µÄ¿Í»§¹ØÏµÖÎÀíϵͳ£¨CRM£©£¬ £¬£¬£¬ËüÌṩÖÎÀí¡¢ÍøÂç¡¢ÆÊÎö¿Í»§ÐÅÏ¢µÈ¹¦Ð§

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Sophos_Firewall_´úÂëÖ´ÐÐ[CVE-2022-3236]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSophosFirewallv19.0MR1(19.0.1)ÒÔ¼°Ö®Ç°°æ±¾Öб£´æµÄ´úÂëÖ´ÐÐÎó²î£¬ £¬£¬£¬´Ó¶øÄ¿µÄϵͳȨÏÞ¡£¡£¡£SophosXGFirewallÊÇSophos¹«Ë¾Äܹ»Íêȫʶ±ðÍøÂçÉϱ»Ñ¬È¾µÄÓû§£¬ £¬£¬£¬²¢×Ô¶¯ÏÞÖÆ¶ÔÆäËûÍøÂç×ÊÔ´µÄ»á¼ûµÄÍøÂçÇå¾²½â¾ö¼Æ»®¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢_E-office10ǰ̨_í§ÒâÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚͨ¹ý·ºÎ¢_E-office10ǰ̨µÄOfficeServer.phpÒ³ÃæÉÏ´«í§ÒâÎļþ£»£»£»Í¨¹ý´ËÎó²î¹¥»÷Õß¿ÉÉÏ´«í§ÒâÃûÌõÄÎļþ£¬ £¬£¬£¬ºó¶ËЧÀÍÆ÷»áÀֳɯÊÎö¸ÃÎļþ£¬ £¬£¬£¬µ¼Ö¿Éͨ¹ý´ËÎó²îÖ±½Ó»ñȡϵͳȨÏÞ¡£¡£¡£·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬ £¬£¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬 £¬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬ £¬£¬£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬠£¬£¬£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬ £¬£¬£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬 £¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬ £¬£¬£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101