ÿÖÜÉý¼¶Í¨¸æ-2021-12-07
Ðû²¼Ê±¼ä 2021-12-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_Çå¾²Îó²î_Apache_ShenYu_Admin_δÊÚȨµÇ¼Îó²î_¹¥»÷ʵÑé[CVE-2021-37580][CNNVD-202111-1500] |
Çå¾²ÀàÐÍ£º | ·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃApache_ShenYu_AdminµÄδÊÚȨµÇ¼Îó²î£¬£¬£¬£¬£¬ÈƹýJSONWebToken(JWT)Çå¾²ÈÏÖ¤£¬£¬£¬£¬£¬Ö±½Ó½øÈëϵͳºǫ́ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | TCP_Çå¾²Îó²î_Dubbo_Hessian2ÐÒé·´ÐòÁл¯Îó²î[CVE-2021-25641] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚͨ¹ý½á¹¹serializationidÀ´¾ÙÐÐδÊÚȨ´úÂëÖ´ÐУ¬£¬£¬£¬£¬Í¨¹ýKryo¡¢FST»òÕßnative-javaµÈÇå¾²ÐԽϲîµÄÐòÁл¯·½·¨¾ÙÐз´ÐòÁл¯´úÂëÖ´ÐУ»£»£»£»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬£¬£¬£¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | TCP_Çå¾²Îó²î_Dubbo_Nashorn¾ç±¾Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-30181] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÔÚ¿ÉÄÜÒѾ¿ØÖÆÈçZooKeeperÉèÖÃÖÐÐĺ󣬣¬£¬£¬£¬Í¨¹ýÉèÖÃÖÐÐÄÀ´½á¹¹¶ñÒâÇëÇó¶ÔDubbo×¢ÈëNashorn¾ç±¾£¬£¬£¬£¬£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ»£»£»£»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬£¬£¬£¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Netgear-ProSAFE-Plus_JGS516PE_δÑéÖ¤Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-26919][CNNVD-202010-350] |
Çå¾²ÀàÐÍ£º | ·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCVE-2020-26919Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¹¥»÷Àֳɣ¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£NetgearProSAFEPlusJGS516PE/GS116Ev2ÊÇÃÀ¹úÍø¼þ(Netgear)¹«Ë¾µÄÒ»¿î½»Á÷»ú¡£¡£NetgearJGS516PEdevices2.6.0.43֮ǰ°æ±¾±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ×°±¸ÔÚ¹¦Ð§¼¶±ðÉÏÊܵ½È±ÉÙ»á¼û¿ØÖÆ¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_WordPress_XSS¾ç±¾×¢ÈëÎó²î[CVE-2019-16219][CNNVD-201909-549] |
Çå¾²ÀàÐÍ£º | XSS¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃNetgea·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£ÔÚNETGEARR7000Éϱ£´æÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Çå¾²Îó²î¡£¡£Îó²îʹÓÃÀֳɺ󣬣¬£¬£¬£¬¿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_thinkcmf_ºǫ́´úÂëÖ´ÐÐÎó²î[CVE-2019-7580][CNNVD-201902-163] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃthinkcmfµÄºǫ́´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ÔÚ·ÖÀàÖÎÀíÒ³Ãæ½¨Éè·ÖÖÖÓÖÃûʱ£¬£¬£¬£¬£¬Ð´Èë¶ñÒâ´úÂë¡£¡£ThinkCMFÊÇÒ»¿îÖ§³ÖSwooleµÄ¿ªÔ´ÄÚÈÝÖÎÀí¿ò¼Ü(CMF),»ùÓÚThinkPHP¿ª·¢¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_Downloader_APT-C-23_ÅþÁ¬_±äÖÖ |
Çå¾²ÀàÐÍ£º | ÏÂÔØÕßľÂí |
ÊÂÎñÐÎò£º | ¼ì²âµ½APT-C-23ÏÂÔØÆ÷ľÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAPT-C-23ÏÂÔØÆ÷ľÂí¡£¡£APT-C-23ÏÂÔØÆ÷ľÂíÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_DedeCMS_sys_verifies.php_´úÂë×¢ÈëÎó²î[CVE-2018-9174][CNNVD-201804-087] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£¡£DeDeCMS5.7°æ±¾ÔÚ±£´æsys_verifies.php´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ¶Ô´«Èë²ÎÊýrefiles¹ýÂ˲»ÑϽ÷£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Phpcms_insdex.php_ǰ̨Getshell |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚʹÓÃPhpcmsǰ̨ע²áÓû§µÄ½çÃæ£¬£¬£¬£¬£¬¾ÙÐÐgetshell²Ù×÷£¬£¬£¬£¬£¬µ«ÏÖÔÚ¹æÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñgetshell£»£»£»£»£»£»£»£»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¡£¸ÃÈí¼þ½ÓÄÉÄ£¿£¿£¿£¿£¿£¿é»¯¿ª·¢£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖ·ÖÀà·½·¨£¬£¬£¬£¬£¬Ê¹ÓÃËü¿ÉÀû±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Phpcms_insdex.php_ºǫ́Getshell |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚʹÓÃPhpcmsºóÌ¨Ò³Ãæ£¬£¬£¬£¬£¬¾ÙÐÐgetshell²Ù×÷£¨ÏÖÔڸùæÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñÒѾgetshell£©£»£»£»£»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¡£¸ÃÈí¼þ½ÓÄÉÄ£¿£¿£¿£¿£¿£¿é»¯¿ª·¢£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖ·ÖÀà·½·¨£¬£¬£¬£¬£¬Ê¹ÓÃËü¿ÉÀû±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_DedeCMS_stepselect_main.php_´úÂë×¢ÈëÎó²î[CVE-2018-9175][CNNVD-201804-086] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£¡£DeDeCMS5.7°æ±¾ÔÚ±£´æstepselect_main.php´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ¶Ô´«Èë²ÎÊýegroup¹ýÂ˲»ÑϽ÷£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_DedeCMS_ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î[CVE-2018-7700][CNNVD-201803-954] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼¡¢ÖÎÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¡£DesdevDedeCMS5.7°æ±¾Öб£´æí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòtag_test_action.phpÎļþ·¢ËÍ¡®partcode¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_VMware_Spring_Cloud_Netflix_´úÂëÖ´ÐÐÎó²î[CVE-2021-22053][CNNVD-202111-1645] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | SpringCloudNetflixÊÇÒ»Ì×ÂþÑÜʽЧÀÍ¿ò¼ÜµÄ·â×°£¬£¬£¬£¬£¬°üÀ¨Ð§À͵ķ¢Ã÷ºÍ×¢²á£¬£¬£¬£¬£¬¸ºÔØÆ½ºâ¡¢¶Ï·Æ÷¡¢REST¿Í»§¶Ë¡¢ÇëÇó·Óɵȡ£¡£¸ÃÎó²îÊÇÓÉÓÚVMwareSpringCloudÔÚͬʱʹÓÃspring-cloud-netflix-hystrix-dashboardºÍspring-boot-starter-thymeleafµÄÓ¦ÓóÌÐòʱ£¬£¬£¬£¬£¬¹ûÕæÁËÔÚÆÊÎöÊÓͼģ°åʱ´úÖ´ÐÐÇëÇóURI·¾¶ÖÐÌá½»½ÓÂëµÄÒªÁì¡£¡£µ±ÔÚ¡®/hystrix/monitor;[user-provideddata]`ÉÏ·¢³öÇëÇóʱ£¬£¬£¬£¬£¬`hystrix/monitor`ºóÃæµÄ·¾¶ÔªËؽ«±»Ê¶±ðΪSpringEL±í´ïʽ£¬£¬£¬£¬£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_DedeCMS_Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼¡¢ÖÎÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¡£DedecmsV5.7SP2°æ±¾ÖеÄtpl.phpÖб£´æ´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÔÚÔöÌíбêÇ©ÖÐÉÏ´«Ä¾Âí£¬£¬£¬£¬£¬»ñÈ¡webshell¡£¡£¸ÃÎó²îʹÓÃÐèÒªµÇ¼ºǫ́£¬£¬£¬£¬£¬²¢ÇÒºǫ́µÄÕË»§È¨ÏÞÊÇÖÎÀíԱȨÏÞ¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | ÷ÈħӰϷ³ÌÐò(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉÆµÄǿʢÊÓÆµÓ°Ï·ÏµÍ³¡£¡£ÍêÉÆÖ§³ÖÖÚ¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬£¬£¬£¬£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¡£¸ÃÎó²î±¬·¢ÔÓÉÓÚ¹ýÂ˲»ÑϽ÷µ¼Ö¹¥»÷Õß¿ÉÒÔÖ±½ÓÔÚÄÚÖÃÄ£°åÖÐ×¢Èë¶ñÒâ´úÂë¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_ÅÀ³æBot»á¼û |
Çå¾²ÀàÐÍ£º | ÍøÒ³ÅÀ³æ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ÅÀ³æBot¶ÔÄ¿µÄIPÖ÷»úµÄweb»á¼û,¿ÉÄÜÔÚ¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐÒ³ÃæÅÀÈ¡¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_TP-LINK_TL-WR840N_EU(V5)_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2021-41653][CNNVD-202111-1211] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | TP-LINKTL-WR840NÊÇÒ»¿îÎÞÏß·ÓÉÆ÷£¬£¬£¬£¬£¬ÐŵÀÊýΪ13£¬£¬£¬£¬£¬Ö§³ÖVPN¹¦Ð§¡£¡£TP-LINKTL-WR840NEU(V5)RouterµÄPING¹¦Ð§±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýIPµØµãÖÐÌØÖÆµÄÓÐÓÃÔØºÉÖ´ÐÐÔ¶³ÌÏÂÁî¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_º£¿£¿£¿£¿£¿£¿µÍþÊÓIPÉãÏñ»ú/NVR_ÏÂÁî×¢ÈëÎó²î[CVE-2021-36260][CNNVD-202109-1602] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | º£¿£¿£¿£¿£¿£¿µÍþÊÓIPÉãÏñ»ú/NVR×°±¸¹Ì¼þÖб£´æÒ»¸öδÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬ÓÉÓÚ¶ÔÊäÈë²ÎÊýУÑé²»³ä·Ö£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍ´øÓжñÒâÏÂÁîµÄ±¨Îĵ½ÊÜÓ°Ïì×°±¸£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔµ¼ÖÂÏÂÁîÖ´ÐС£¡£º£¿£¿£¿£¿£¿£¿µÍþÊÓÒÑÐû²¼°æ±¾ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìIPÉãÏñÍ·ºÍNVR×°±¸¹Ì¼þ£¬£¬£¬£¬£¬ÆäÖаüÀ¨2021Äê6ÔµÄ×îй̼þÒÔ¼°2006ÄêÐû²¼µÄ¹Ì¼þ¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Ç徲ɨÃè_WEBɨÃèÆ÷ÐÐΪ |
Çå¾²ÀàÐÍ£º | ÍøÂçɨÃè |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPµØµãµÄÖ÷»úÕýÔÚʹÓÃWEBɨÃ蹤¾ß(È磺sqlmap¡¢nessusµÈ)¶ÔÄ¿µÄIPµØµã¾ÙÐÐÎó²îɨÃè¡£¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×öЧÀÍɨÃè¡¢Îó²î²âÊԵȡ£¡£Í¨¹ýÎó²îɨÃ裬£¬£¬£¬£¬¿ÉÒÔ×Ô¶¯¿ìËÙ̽²âһЩ³£¼ûÎó²îÇéÐΣ¬£¬£¬£¬£¬µ±±£´æÎó²îʱ±ãÓÚºóÐø¾ÙÐÐʹÓù¥»÷¡£¡£ |
¸üÐÂʱ¼ä£º | 20211207 |