ÿÖÜÉý¼¶Í¨¸æ-2022-11-01

Ðû²¼Ê±¼ä 2022-11-01
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_drag-and-drop-multiple-file-uploader_ÎļþÉÏ´«[CVE-2020-12800][CNNVD-202006-519]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWordPressdraganddropmultiplefileuploader²å¼þ1.3.3.3֮ǰ°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î£¬£¬ £¬´Ó¶ø»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£¡£¡£¡£DragandDropMultipleFileUploaderÊÇContactForm7µÄÒ»¸ö¼òÆÓ¡¢Ö±½ÓµÄWordPress²å¼þÀ©Õ¹£¬£¬ £¬ËüÔÊÐíÓû§Ê¹ÓÃÍϷŹ¦Ð§»òWeb±íµ¥µÄͨÓÃä¯ÀÀÎļþÉÏ´«¶à¸öÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_vTiger_CRM_ÎļþÉÏ´«[CVE-2013-3591][CNNVD-201310-746]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃvTigerCRM5.3.0ÒÔ¼°5.4.0°æ±¾Öб£´æµÄÎļþÉÏ´«Îó²î£¬£¬ £¬´Ó¶øÔÚÉϰ¶ºó»ñȡĿµÄϵͳµÄȨÏÞ¡£¡£¡£¡£¡£¡£VtigerCRMÊÇÃÀ¹úVtiger¹«Ë¾µÄÒ»Ì×»ùÓÚSugarCRM¿ª·¢µÄ¿Í»§¹ØÏµÖÎÀíϵͳ£¨CRM£©£¬£¬ £¬ËüÌṩÖÎÀí¡¢ÍøÂç¡¢ÆÊÎö¿Í»§ÐÅÏ¢µÈ¹¦Ð§

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Sophos_Firewall_´úÂëÖ´ÐÐ[CVE-2022-3236]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃSophosFirewallv19.0MR1(19.0.1)ÒÔ¼°Ö®Ç°°æ±¾Öб£´æµÄ´úÂëÖ´ÐÐÎó²î£¬£¬ £¬´Ó¶øÄ¿µÄϵͳȨÏÞ¡£¡£¡£¡£¡£¡£SophosXGFirewallÊÇSophos¹«Ë¾Äܹ»Íêȫʶ±ðÍøÂçÉϱ»Ñ¬È¾µÄÓû§£¬£¬ £¬²¢×Ô¶¯ÏÞÖÆ¶ÔÆäËûÍøÂç×ÊÔ´µÄ»á¼ûµÄÍøÂçÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢_E-office10ǰ̨_í§ÒâÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚͨ¹ý·ºÎ¢_E-office10ǰ̨µÄOfficeServer.phpÒ³ÃæÉÏ´«í§ÒâÎļþ£»£»£»Í¨¹ý´ËÎó²î¹¥»÷Õß¿ÉÉÏ´«í§ÒâÃûÌõÄÎļþ£¬£¬ £¬ºó¶ËЧÀÍÆ÷»áÀֳɯÊÎö¸ÃÎļþ£¬£¬ £¬µ¼Ö¿Éͨ¹ý´ËÎó²îÖ±½Ó»ñȡϵͳȨÏÞ¡£¡£¡£¡£¡£¡£·ºÎ¢ÊÇÓÉ·ºÎ¢ÍøÂ翪·¢µÄOAϵͳ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬ £¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬ £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬ £¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬣¬ £¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬£¬ £¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬£¬ £¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬ £¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221101