ÿÖÜÉý¼¶Í¨¸æ-2022-09-20

Ðû²¼Ê±¼ä 2022-09-20

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Pi-hole_v4.4_ÎļþÉÏ´«[CVE-2020-11108][CNNVD-202005-403]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Pi-holeÊÇÒ»¸öÓÃÓÚÄÚÈݹýÂ˵ÄDNSЧÀÍÆ÷£¬ £¬£¬£¬£¬v4.4¼°Æä֮ǰµÄ°æ±¾±£´æÎļþÉÏ´«Îó²î£¬ £¬£¬£¬£¬ÔÚ¹¥»÷ÕߵǼºó¿ÉÒÔÉÏ´«¶ñÒâwebshell»ñȡϵͳȨÏÞ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Online-Voting-System_1.0_ÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OnlineVotingSystemÊÇרÃÅΪCHMSCµÄÖÐѧ/¸ßÖпª·¢µÄϵͳ£¬ £¬£¬£¬£¬Æä1.0¼°Æä֮ǰµÄ°æ±¾±£´æÎļþÉÏ´«Îó²î£¬ £¬£¬£¬£¬ÔÚ¹¥»÷ÕߵǼºó¿ÉÒÔÉÏ´«¶ñÒâwebshell»ñȡϵͳȨÏÞ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_actuator_heapdump_·ÇÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Spring¿ò¼ÜÖеÄactuator×é¼þ±£´æÎ´ÊÚȨ»á¼ûÎó²î£¬ £¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý»á¼ûurl+/actuator/heapdump»ñȡЧÀÍÆ÷Ãô¸ÐÄÚ´æÐÅÏ¢¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Ewebeditor_aStyleÆø¸Å½ç˵_ÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PHP°æ±¾µÄewebeditor²¢Ã»ÓÐʹÓÃÊý¾Ý¿âÀ´ÉúÑÄÉèÖÃÐÅÏ¢£¬ £¬£¬£¬£¬ËùÓÐÐÅϢλÓÚphp/config.phpÖУ¬ £¬£¬£¬£¬Ëü½«ËùÓÐµÄÆø¸ÅÉèÖÃÐÅÏ¢ÉúÑÄΪһ¸öÊý×é$aStyle,ÔÚregister_globalΪonµÄÇéÐÎÏÂÎÒÃÇ¿ÉÒÔí§ÒâÌí¼Ó×Ô¼ºÏ²»¶µÄÆø¸Å£¬ £¬£¬£¬£¬È»ºó¾Í¿ÉÒÔÔÚ×Ô¼ºÌí¼ÓµÄÆø¸ÅÖпÉÒÔËæÒâ½ç˵¿ÉÉÏ´«ÎļþÀàÐÍ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_spring-data_mongodb_SpEL±í´ïʽעÈë[CVE-2022-22980]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

SpringDataforMongoDBÊÇSpringDataÏîÄ¿µÄÒ»²¿·Ö£¬ £¬£¬£¬£¬¸ÃÏîĿּÔÚΪÐÂÊý¾Ý´æ´¢ÌṩÊìϤÇÒÒ»ÖµĻùÓÚSpringµÄ±à³ÌÄ£×Ó£¬ £¬£¬£¬£¬Í¬Ê±±£´æÌض¨ÓÚ´æ´¢µÄÌØÕ÷ºÍ¹¦Ð§¡£¡£¡£¡£¡£SpringDataMongoDBÏîÄ¿ÌṩÓëMongoDBÎĵµÊý¾Ý¿âµÄ¼¯³É¡£¡£¡£¡£¡£SpringDataMongoDBµÄÒªº¦¹¦Ð§ÊÇÒÔPOJOΪÖÐÐĵÄÄ£×Ó£¬ £¬£¬£¬£¬ÓÃÓÚÓëMongoDBDBCollection½»»¥²¢ÇáËɱàдRepositoryÑùʽµÄÊý¾Ý»á¼û²ã¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Imagetragick_ͼƬ´¦Öóͷ£Ä£¿£¿£¿£¿é_ÏÂÁîÖ´ÐÐ[CVE-2016-3714]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ImageMagickÊÇÒ»¿îʹÓÃÁ¿ºÜ¹ãµÄͼƬ´¦Öóͷ£³ÌÐò£¬ £¬£¬£¬£¬Ðí¶à³§É̶¼Å²ÓÃÁËÕâ¸ö³ÌÐò¾ÙÐÐͼƬ´¦Öóͷ££¬ £¬£¬£¬£¬°üÀ¨Í¼Æ¬µÄÉìËõ¡¢Çиˮӡ¡¢ÃûÌÃת»»µÈµÈ¡£¡£¡£¡£¡£µ«åÇÀ´ÓÐÑо¿Õß·¢Ã÷£¬ £¬£¬£¬£¬µ±Óû§´«ÈëÒ»¸ö°üÀ¨¡º»ûÐÎÄÚÈÝ¡»µÄͼƬµÄʱ¼ä£¬ £¬£¬£¬£¬¾ÍÓпÉÄÜ´¥·¢ÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_JAVAÄÚ´æÂí¹¥»÷_±äÐÎ3_Webshell»á¼û

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

ÄÚ´æÂí¹¥»÷ÊÇÒ»ÖÖʹÓÃÏà¹ØÊֶεִïÎÞÎļþÂäµØÐ§¹ûµÄwebshell¹¥»÷ÊֶΣ¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÄÚ´æÂí¾ÙÐг¤Ê±¼ä¸ßÒþ²ØÐÔµÄwebsehll¹¥»÷¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_OKLIite_v1.2.25_ÎļþÉÏ´«[CVE-2019-16131][CNNVD-201909-300]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OKLiteÊÇÒ»Ì×»ùÓÚphpµÄÆóÒµ½¨Õ¾ÄÚÈÝÖÎÀíϵͳ£¬ £¬£¬£¬£¬Æäv1.2.25°æ±¾ÒÔ¼°¸üµÍ°æ±¾Öб£´æºǫ́ÎļþÉÏ´«Îó²î£¬ £¬£¬£¬£¬Éϰ¶ºóµÄ¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÉÏ´«í§ÒâÎļþ£¬ £¬£¬£¬£¬»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20220920

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÆäËü¿ÉÒÉÐÐΪ_дÈëjarÎļþ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

ÔÚJAVAÖУ¬ £¬£¬£¬£¬java.io.FileOutputStream¿ÉÒÔÓÃÀ´ÎļþдÈ룬 £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÀàдÈë¶ñÒâjar°ü£¬ £¬£¬£¬£¬ÅäºÏÆäËüÎó²î¼°ÊÖ·¨´Ó¶ø»ñȡĿµÄIP×°±¸È¨ÏÞ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ZooKeeper_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃZooKeeper±£´æµÄδÊÚȨ»á¼ûÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£ZooKeeperÊÇÒ»¸öÂþÑÜʽµÄ£¬ £¬£¬£¬£¬¿ª·ÅÔ´ÂëµÄÂþÑÜʽӦÓóÌÐòЭµ÷ЧÀÍ£¬ £¬£¬£¬£¬ÊÇGoogleµÄChubbyÒ»¸ö¿ªÔ´µÄʵÏÖ£¬ £¬£¬£¬£¬ÊÇHadoopºÍHbaseµÄÖ÷Òª×é¼þ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220920