ÿÖÜÉý¼¶Í¨¸æ-2021-12-07

Ðû²¼Ê±¼ä 2021-12-10

ÐÂÔöÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Apache_ShenYu_Admin_δÊÚȨµÇ¼Îó²î_¹¥»÷ʵÑé[CVE-2021-37580][CNNVD-202111-1500]

Çå¾²ÀàÐÍ£º

·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃApache_ShenYu_AdminµÄδÊÚȨµÇ¼Îó²î£¬£¬£¬£¬£¬ÈƹýJSONWebToken(JWT)Çå¾²ÈÏÖ¤£¬£¬£¬£¬£¬Ö±½Ó½øÈëϵͳºǫ́

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Dubbo_Hessian2ЭÒé·´ÐòÁл¯Îó²î[CVE-2021-25641]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚͨ¹ý½á¹¹serializationidÀ´¾ÙÐÐδÊÚȨ´úÂëÖ´ÐУ¬£¬£¬£¬£¬Í¨¹ýKryo¡¢FST»òÕßnative-javaµÈÇå¾²ÐԽϲîµÄÐòÁл¯·½·¨¾ÙÐз´ÐòÁл¯´úÂëÖ´ÐУ»£»£» £»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬£¬£¬£¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Dubbo_Nashorn¾ç±¾Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-30181]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÔÚ¿ÉÄÜÒѾ­¿ØÖÆÈçZooKeeperÉèÖÃÖÐÐĺ󣬣¬£¬£¬£¬Í¨¹ýÉèÖÃÖÐÐÄÀ´½á¹¹¶ñÒâÇëÇó¶ÔDubbo×¢ÈëNashorn¾ç±¾£¬£¬£¬£¬£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ»£»£» £»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬£¬£¬£¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£

¸üÐÂʱ¼ä£º

20211207

 


ÊÂÎñÃû³Æ£º

 HTTP_Netgear-ProSAFE-Plus_JGS516PE_δÑéÖ¤Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-26919][CNNVD-202010-350]

Çå¾²ÀàÐÍ£º

·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCVE-2020-26919Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¹¥»÷Àֳɣ¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁî¡£¡£NetgearProSAFEPlusJGS516PE/GS116Ev2ÊÇÃÀ¹úÍø¼þ(Netgear)¹«Ë¾µÄÒ»¿î½»Á÷»ú¡£¡£NetgearJGS516PEdevices2.6.0.43֮ǰ°æ±¾±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ×°±¸ÔÚ¹¦Ð§¼¶±ðÉÏÊܵ½È±ÉÙ»á¼û¿ØÖÆ¡£¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_WordPress_XSS¾ç±¾×¢ÈëÎó²î[CVE-2019-16219][CNNVD-201909-549]

Çå¾²ÀàÐÍ£º

XSS¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃNetgea·ÓÉÆ÷Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£ÔÚNETGEARR7000Éϱ£´æÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Çå¾²Îó²î¡£¡£Îó²îʹÓÃÀֳɺ󣬣¬£¬£¬£¬¿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_thinkcmf_ºǫ́´úÂëÖ´ÐÐÎó²î[CVE-2019-7580][CNNVD-201902-163]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃthinkcmfµÄºǫ́´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬ÔÚ·ÖÀàÖÎÀíÒ³Ãæ½¨Éè·ÖÖÖÓÖÃûʱ£¬£¬£¬£¬£¬Ð´Èë¶ñÒâ´úÂë¡£¡£ThinkCMFÊÇÒ»¿îÖ§³ÖSwooleµÄ¿ªÔ´ÄÚÈÝÖÎÀí¿ò¼Ü(CMF),»ùÓÚThinkPHP¿ª·¢¡£¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Downloader_APT-C-23_ÅþÁ¬_±äÖÖ

Çå¾²ÀàÐÍ£º

ÏÂÔØÕßľÂí

ÊÂÎñÐÎò£º

¼ì²âµ½APT-C-23ÏÂÔØÆ÷ľÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAPT-C-23ÏÂÔØÆ÷ľÂí¡£¡£APT-C-23ÏÂÔØÆ÷ľÂíÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_sys_verifies.php_´úÂë×¢ÈëÎó²î[CVE-2018-9174][CNNVD-201804-087]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£¡£DeDeCMS5.7°æ±¾ÔÚ±£´æsys_verifies.php´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ¶Ô´«Èë²ÎÊýrefiles¹ýÂ˲»ÑϽ÷£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£

¸üÐÂʱ¼ä£º

20211207


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Phpcms_insdex.php_ǰ̨Getshell

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚʹÓÃPhpcmsǰ̨ע²áÓû§µÄ½çÃæ£¬£¬£¬£¬£¬¾ÙÐÐgetshell²Ù×÷£¬£¬£¬£¬£¬µ«ÏÖÔÚ¹æÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñgetshell£»£»£» £»£»£»£» £»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¡£¸ÃÈí¼þ½ÓÄÉÄ£¿£¿£¿£¿ £¿£¿é»¯¿ª·¢£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖ·ÖÀà·½·¨£¬£¬£¬£¬£¬Ê¹ÓÃËü¿ÉÀû±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Phpcms_insdex.php_ºǫ́Getshell

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ip¿ÉÄÜÕýÔÚʹÓÃPhpcmsºóÌ¨Ò³Ãæ£¬£¬£¬£¬£¬¾ÙÐÐgetshell²Ù×÷£¨ÏÖÔڸùæÔòÎÞ·¨×¼È·ÅжÏÊÇ·ñÒѾ­getshell£©£»£»£» £»PHPCMSÊÇÒ»¿îÍøÕ¾ÖÎÀíÈí¼þ¡£¡£¸ÃÈí¼þ½ÓÄÉÄ£¿£¿£¿£¿ £¿£¿é»¯¿ª·¢£¬£¬£¬£¬£¬Ö§³Ö¶àÖÖ·ÖÀà·½·¨£¬£¬£¬£¬£¬Ê¹ÓÃËü¿ÉÀû±ãʵÏÖ¸öÐÔ»¯ÍøÕ¾µÄÉè¼Æ¡¢¿ª·¢Óëά»¤¡£¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_stepselect_main.php_´úÂë×¢ÈëÎó²î[CVE-2018-9175][CNNVD-201804-086]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£¡£DeDeCMS5.7°æ±¾ÔÚ±£´æstepselect_main.php´úÂë×¢ÈëÎó²î£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ¶Ô´«Èë²ÎÊýegroup¹ýÂ˲»ÑϽ÷£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉʹÓôËÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£

¸üÐÂʱ¼ä£º

20211207

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î[CVE-2018-7700][CNNVD-201803-954]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼­¡¢ÖÎÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¡£DesdevDedeCMS5.7°æ±¾Öб£´æí§Òâ´úÂëÖ´ÐÐÎó²î¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòtag_test_action.phpÎļþ·¢ËÍ¡®partcode¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_VMware_Spring_Cloud_Netflix_´úÂëÖ´ÐÐÎó²î[CVE-2021-22053][CNNVD-202111-1645]

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

SpringCloudNetflixÊÇÒ»Ì×ÂþÑÜʽЧÀÍ¿ò¼ÜµÄ·â×°£¬£¬£¬£¬£¬°üÀ¨Ð§À͵ķ¢Ã÷ºÍ×¢²á£¬£¬£¬£¬£¬¸ºÔØÆ½ºâ¡¢¶Ï·Æ÷¡¢REST¿Í»§¶Ë¡¢ÇëÇó·Óɵȡ£¡£¸ÃÎó²îÊÇÓÉÓÚVMwareSpringCloudÔÚͬʱʹÓÃspring-cloud-netflix-hystrix-dashboardºÍspring-boot-starter-thymeleafµÄÓ¦ÓóÌÐòʱ£¬£¬£¬£¬£¬¹ûÕæÁËÔÚÆÊÎöÊÓͼģ°åʱ´úÖ´ÐÐÇëÇóURI·¾¶ÖÐÌá½»½ÓÂëµÄÒªÁì¡£¡£µ±ÔÚ¡®/hystrix/monitor;[user-provideddata]`ÉÏ·¢³öÇëÇóʱ£¬£¬£¬£¬£¬`hystrix/monitor`ºóÃæµÄ·¾¶ÔªËؽ«±»Ê¶±ðΪSpringEL±í´ïʽ£¬£¬£¬£¬£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¡£

¸üÐÂʱ¼ä£º

20211207


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DedeCMS_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

DedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈÝÐû²¼¡¢±à¼­¡¢ÖÎÀí¼ìË÷¼´ÊÇÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£¡£DedecmsV5.7SP2°æ±¾ÖеÄtpl.phpÖб£´æ´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÔÚÔöÌíбêÇ©ÖÐÉÏ´«Ä¾Âí£¬£¬£¬£¬£¬»ñÈ¡webshell¡£¡£¸ÃÎó²îʹÓÃÐèÒªµÇ¼ºǫ́£¬£¬£¬£¬£¬²¢ÇÒºǫ́µÄÕË»§È¨ÏÞÊÇÖÎÀíԱȨÏÞ¡£¡£

¸üÐÂʱ¼ä£º

20211207



ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÐÎò£º

÷ÈħӰϷ³ÌÐò(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉÆµÄǿʢÊÓÆµÓ°Ï·ÏµÍ³¡£¡£ÍêÉÆÖ§³ÖÖÚ¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬£¬£¬£¬£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¡£¸ÃÎó²î±¬·¢Ô­ÓÉÓÚ¹ýÂ˲»ÑϽ÷µ¼Ö¹¥»÷Õß¿ÉÒÔÖ±½ÓÔÚÄÚÖÃÄ£°åÖÐ×¢Èë¶ñÒâ´úÂë¡£¡£

¸üÐÂʱ¼ä£º

20211207


 

ÊÂÎñÃû³Æ£º

HTTP_ÅÀ³æBot»á¼û

Çå¾²ÀàÐÍ£º

ÍøÒ³ÅÀ³æ

ÊÂÎñÐÎò£º

¼ì²âµ½ÅÀ³æBot¶ÔÄ¿µÄIPÖ÷»úµÄweb»á¼û,¿ÉÄÜÔÚ¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐÒ³ÃæÅÀÈ¡¡£¡£

¸üÐÂʱ¼ä£º

20211207

 

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_TP-LINK_TL-WR840N_EU(V5)_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2021-41653][CNNVD-202111-1211]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

TP-LINKTL-WR840NÊÇÒ»¿îÎÞÏß·ÓÉÆ÷£¬£¬£¬£¬£¬ÐŵÀÊýΪ13£¬£¬£¬£¬£¬Ö§³ÖVPN¹¦Ð§¡£¡£TP-LINKTL-WR840NEU(V5)RouterµÄPING¹¦Ð§±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýIPµØµãÖÐÌØÖÆµÄÓÐÓÃÔØºÉÖ´ÐÐÔ¶³ÌÏÂÁî¡£¡£

¸üÐÂʱ¼ä£º

20211207

 


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_º£¿£¿£¿£¿ £¿£¿µÍþÊÓIPÉãÏñ»ú/NVR_ÏÂÁî×¢ÈëÎó²î[CVE-2021-36260][CNNVD-202109-1602]

Çå¾²ÀàÐÍ£º

ÏÂÁîÖ´ÐÐ

ÊÂÎñÐÎò£º

º£¿£¿£¿£¿ £¿£¿µÍþÊÓIPÉãÏñ»ú/NVR×°±¸¹Ì¼þÖб£´æÒ»¸öδÈÏÖ¤ÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬ÓÉÓÚ¶ÔÊäÈë²ÎÊýУÑé²»³ä·Ö£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍ´øÓжñÒâÏÂÁîµÄ±¨Îĵ½ÊÜÓ°Ïì×°±¸£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔµ¼ÖÂÏÂÁîÖ´ÐС£¡£º£¿£¿£¿£¿ £¿£¿µÍþÊÓÒÑÐû²¼°æ±¾ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìIPÉãÏñÍ·ºÍNVR×°±¸¹Ì¼þ£¬£¬£¬£¬£¬ÆäÖаüÀ¨2021Äê6ÔµÄ×îй̼þÒÔ¼°2006ÄêÐû²¼µÄ¹Ì¼þ¡£¡£

¸üÐÂʱ¼ä£º

20211207

 

ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

HTTP_Ç徲ɨÃè_WEBɨÃèÆ÷ÐÐΪ

Çå¾²ÀàÐÍ£º

ÍøÂçɨÃè

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãµÄÖ÷»úÕýÔÚʹÓÃWEBɨÃ蹤¾ß(È磺sqlmap¡¢nessusµÈ)¶ÔÄ¿µÄIPµØµã¾ÙÐÐÎó²îɨÃè¡£¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×öЧÀÍɨÃè¡¢Îó²î²âÊԵȡ£¡£Í¨¹ýÎó²îɨÃ裬£¬£¬£¬£¬¿ÉÒÔ×Ô¶¯¿ìËÙ̽²âһЩ³£¼ûÎó²îÇéÐΣ¬£¬£¬£¬£¬µ±±£´æÎó²îʱ±ãÓÚºóÐø¾ÙÐÐʹÓù¥»÷¡£¡£

¸üÐÂʱ¼ä£º

20211207