ÿÖÜÉý¼¶Í¨¸æ-2021-11-30

Ðû²¼Ê±¼ä 2021-12-10

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_´úÂëÖ´ÐÐ[CVE-2017-6361][CNNVD-201702-940]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý £¬ £¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁîÖ´ÐÐ[CVE-2017-6360][CNNVD-201702-941]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý £¬ £¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî £¬ £¬£¬£¬»ñÈ¡ÖÎÀíԱȨÏÞºÍÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_QNAP-QTS_ÏÂÁîÖ´ÐÐ[CVE-2017-6359][CNNVD-201702-942]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¡£¡£¡£¡£¡£¸Ãϵͳ¿ÉÌṩµµ°¸Öü´æ¡¢ÖÎÀí¡¢±¸·Ý £¬ £¬£¬£¬¶àýÌåÓ¦Óü°Çå¾²¼à¿ØµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡ÖÎÀíԱȨÏÞ £¬ £¬£¬£¬Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

 TCP_Çå¾²Îó²î_Hadoop_Yarn_RPCδÊÚȨ»á¼ûÎó²î

Çå¾²ÀàÐÍ£º

·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃHadoopYarnµÄÎó²î¾ÙÐÐδÊÚȨ»á¼û£»£»£»£» £»£»¹ØÓÚ8032̻¶ÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager £¬ £¬£¬£¬±àдӦÓóÌÐòŲÓÃyarnClient.getApplications()¼´¿ÉÉó²éËùÓÐÓ¦ÓÃÐÅÏ¢£»£»£»£» £»£»Hadoop×÷Ϊһ¸öÂþÑÜʽÅÌËãÓ¦Óÿò¼Ü £¬ £¬£¬£¬ÖÖÀ๦Ч·±¶à £¬ £¬£¬£¬¶øHadoopYarn×÷ΪÆä½¹µã×é¼þÖ®Ò»¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_CouchDB_JSON_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-12636][CNNVD-201711-486]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃApacheCouchDBJSONÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£¡£¡£ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â £¬ £¬£¬£¬×¨×¢ÓÚÒ×ÓÃÐԺͳÉΪ"Íêȫӵ±§webµÄÊý¾Ý¿â"¡£¡£¡£¡£¡£¡£CouchDB»áĬÈÏ»áÔÚ5984¶Ë¿Ú¿ª·ÅRestfulµÄAPI½Ó¿Ú £¬ £¬£¬£¬ÓÃÓÚÊý¾Ý¿âµÄÖÎÀí¹¦Ð§¡£¡£¡£¡£¡£¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌà £¬ £¬£¬£¬JavaScript×÷ΪÅÌÎÊÓïÑÔ £¬ £¬£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£¡£CouchDB½ÓÄÉ»ùÓÚErlangµÄJSONÆÊÎöÆ÷ £¬ £¬£¬£¬Óë»ùÓÚJavaScriptµÄJSONÆÊÎöÆ÷²î±ð £¬ £¬£¬£¬CouchDB¿ÉÒÔÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇɫ֨¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ»á¼û¿ØÖÆ £¬ £¬£¬£¬ÉõÖÁ°üÀ¨ÌåÏÖÖÎÀíÓû§µÄ_admin½ÇÉ«¡£¡£¡£¡£¡£¡£¶ñÒâ¹¥»÷ÕßʹÓÃÕâÒ»¹¦Ð§²¢Á¬ÏµCVE-2017-12636Îó²î £¬ £¬£¬£¬¿ÉÒÔʹ·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâshellÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Netgear_Nighthawk_R7000δÊÚȨԶ³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-31802]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃNetgea·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£¡£¡£ÔÚNETGEARR7000Éϱ£´æÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Çå¾²Îó²î¡£¡£¡£¡£¡£¡£Îó²îʹÓÃÀÖ³Éºó £¬ £¬£¬£¬¿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

 HTTP_Çå¾²Îó²î_Primefaces_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-1000486][CNNVD-201801-112]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

PrimeFacesÊÇÒ»¸ö¿ªÔ´Óû§½çÃæ(UI)×é¼þ¿â £¬ £¬£¬£¬ÓÃÓÚ»ùÓÚJavaServerFacesµÄÓ¦ÓóÌÐò £¬ £¬£¬£¬ÓÉÍÁ¶úÆä¹«Ë¾PrimeTekInformatics½¨Éè¡£¡£¡£¡£¡£¡£Primefaces5.x±£´æÈõ¼ÓÃÜÎó²î £¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-Link_DWL-2600AP_²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î[CVE-2019-20499/CVE-2019-20500/CVE-2019-20501][CNNVD-202003-201/CNNVD-202003-205/CNNVD-202003-204]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

D-LinkDWL-2600APÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß½ÓÈëµã×°±¸¡£¡£¡£¡£¡£¡£D-LinkDWL-2600AP4.2.0.15RevA°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õ߿ɽèÖúÉúÑÄÉèÖù¦Ð§Ê¹ÓøÃÎó²îÖ´ÐÐí§ÒâµÄ²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Terramaster_TOS_ÏÂÁî×¢ÈëÎó²î[CVE-2020-35665]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×ÓÊÖÒÕ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ £¬ £¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NASЧÀÍÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î £¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýÔÚÊÂÎñ²ÎÊýÖаüÀ¨makecvs.php×¢Èë²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_SQL_Server_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0618][CNNVD-202002-496]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿âÖÎÀíϵͳ(RDBMS) £¬ £¬£¬£¬ÊÇÏÖÔÚÌìÏÂÉÏÆÕ±éʹÓõÄÊý¾Ý¿âÖ®Ò»¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢ËÍÈ«ÐĽṹµÄÇëÇó £¬ £¬£¬£¬¿ÉʹÓôËÎó²îÔÚ±¨±íЧÀÍÆ÷ЧÀÍÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_ÆïÊ¿CMSÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-35339][CNNVD-202102-1295]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÆïÊ¿CMSµÄ¡°ÍøÕ¾ÓòÃû¡±¶ÔÓ¦²ÎÊý¾ÙÐдúÂëÖ´ÐвÙ×÷£»£»£»£» £»£»ÆïÊ¿È˲ÅϵͳÊÇÒ»Ïî»ùÓÚPHPMYSQLΪ½¹µã¿ª·¢µÄÒ»Ì×Ãâ·Ñ¿ªÔ´×¨ÒµÈ˲ÅÕÐÆ¸ÏµÍ³¡£¡£¡£¡£¡£¡£ÎªÐ¡ÎÒ˽¼ÒÇóÖ°ºÍÆóÒµÕÐÆ¸ÌṩÐÅÏ¢»¯½â¾ö¼Æ»®,ÆïÊ¿È˲Åϵͳ¾ß±¸Ö´ÐÐЧÂʸߡ¢Ä£°åÇл»×ÔÓÉ¡¢ºǫ́ÖÎÀí¹¦Ð§ÎÞа¡¢Ä£¿£¿£¿é¹¦Ð§Ç¿Ê¢µÈÌØµã¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_XStream_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-26217][CNNVD-202011-1441]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

Xstream½â×éʱ´¦Öóͷ£µÄÁ÷°üÀ¨ÀàÐÍÐÅÏ¢ÒÔÖØÐ½¨ÉèÒÔǰ±àдµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£XStreamÒò´Ë»ùÓÚÕâЩÀàÐÍÐÅÏ¢½¨ÉèÐÂʵÀý¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô¦Öóͷ£¹ýµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢Èë¿ÉÒÔÖ´ÐÐí§ÒâshellÏÂÁîµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130


ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÏÂÁîÎó²î

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

÷ÈħӰϷ³ÌÐò(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉÆµÄǿʢÊÓÆµÓ°Ï·ÏµÍ³¡£¡£¡£¡£¡£¡£ÍêÉÆÖ§³ÖÖÚ¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ) £¬ £¬£¬£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¡£¡£¡£¡£¡£¸ÃÎó²îÖ÷ÒªµÄ±¬·¢Ôµ¹ÊÔ­ÓÉÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20211130