ÿÖÜÉý¼¶²¼¸æ-2021-12-28

°ä²¼¹¦·ò 2021-12-28

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©³¨ÆðÍ·ÀûÓÃ[MS17-010][CNNVD-201703-726]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅÖ÷»ú½øÐÐMS17-010·ì϶ÀûÓõÄÐÐΪ £¬¸Ã½×¶ÎΪ·ì϶ÀûÓõijõʼ½×¶Î¡£MicrosoftWindowsÊÇ΢Èí°ä²¼µÄ¼«¶ÈÊ¢ÐеIJÙ×÷ϵͳ¡£ÈôÊǹ¥»÷ÕßÏòMicrosoft·þÎñÆ÷·¢Ë;­¾«ÐÄ»ú¹ØµÄ»ûÐÎÒªÇó°ü £¬Äܹ»»ñȡָ±ê·þÎñÆ÷µÄϵͳȨÏÞ £¬²¢ÇÒÆëÈ«½ÚÔìÖ¸±êϵͳ¡£¹¥»÷Õ߯ðÍ·½øÐÐMS17-010·ì϶ÀûÓà £¬ÔÚ±¾»ú´æÔÚ·ì϶µÄÇé¿öÏ £¬ÔÚÀûÓÃʵÏÖºó¹¥»÷Õß¿ÉÄÜÆëÈ«½ÚÔìÖ÷»ú¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Spring-Data-REST-PATCHÒªÇó_Ô¶³ÌÖ´ÐдúÂë[CVE-2017-8046]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

2017Äê9ÔÂ21ÈÕ £¬Ê¢ÐеÄJava¿ò¼Üspring±»·¢ÏÖÒ»¸ö¸ßΣ·ì϶ £¬·ì϶CVE±àºÅΪCVE-2017-8046¡£ºÚ¿ÍÄܹ»ÀûÓø÷ì϶Զ³ÌÖ´ÐкÅÁî £¬Ê¹ÓÃÁËspring¿ò¼ÜµÄÒµÎñ´æÔڸ߰²È«·çÏÕ¡£SpringDataRestÊÇSpringData¿ò¼ÜµÄÆäÖÐÒ»¸ö×é¼þ £¬SpringDataRest¿É¹¹½¨RestWeb £¬SpringDataRest¶ÔPATCH²½Öè´¦Öò»µ± £¬µ¼Ö¹¥»÷Õß¿ÉÄÜÀûÓÃJSONÊý¾ÝÔì³ÉRCE¡£ÐÔÖÊ»¹ÊÇÓÉÓÚSpringµÄSPEL½âÎöµ¼ÖµÄRCE¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Intellian_Satellian_Aptus_WebÔ¶³Ì´úÂëÖ´ÐÐ[CVE-2020-7980]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

Intellian Satellian Aptus Web ÊÇÒ»¸ö½ÚÔį̀ϵͳ¡£ÔÚIntellian Aptus Web 1.24 ֮ǰµÄ°æ±¾ÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ý JSON Êý¾ÝÖÐµÄ Q ×Ö¶ÎÏò/cgi-bin/libagent.cgi Ö´ÐÐËÁÒâ OS ºÅÁî¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_ºÅÁîÖ´ÐÐ_Alcatel-Lucent_OmniPCX_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2007-3010][CNNVD-200709-257]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃAlcatelR7.1°æ±¾ÒÔǰµÄ·ì϶½øÐкÅÁîÖ´ÐУ»Alcatel_OmniPCXEnterpriseÊÇÒ»ÖÖÕë¶Ô´óÖÐÐÍÆóÒµ¡¢±ö¹Ý¡¢ºô½ÐÖÐÐĵɽ»»¥Ê½Í¨Ñ¶½â¾ö¹æ»®¡£¸Ã½â¾ö¹æ»®½«´«Í³µÄµç»°Ö°ÄܺͶԻùÓÚÒòÌØÍøµÄÓïÒôͨѶ¼°¶àýÌåͨѶµÄÖ§³ÖÏà½áºÏ¡£AlcatelOmniPCXEnterpriseÊÇ»ùÓÚÒµ½ç³ß¶ÈµÄÊ¢¿ªÐÍ¡¢É¢²¼Ê½Í¨ÕÛ·þÎñÆ÷ £¬ºÏÓÃÓÚ´óÖÐÐÍÆóÒµµÄͨѶҵÎñ¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ÐÅϢй¶·ì϶[CVE-2018-6910][CNNVD-201802-949]

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

DesdevDedeCMS£¨Ö¯ÃÎÄÚÈÝÖÎÀíϵͳ£©ÊÇÖйú×¿×¿ÍøÂ磨Desdev£©¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼¯ÄÚÈݰ䲼¡¢±à×ë¡¢ÖÎÀí¼ìË÷µÅ×ÚÒ»ÌåµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ£¨CMS£©¡£DesdevDedeCMS5.7°æ±¾ÖдæÔÚÐÅϢй¶·ì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý¶Ôinclude/downmix.inc.php»òinc/inc_archives_functions.phpÎļþ·¢ËͽÓÒªÇóÀûÓø÷ì϶»ñÈ¡ÆëÈ«õè¾¶¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Apache_Druid_LoadData_ËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2021-36749][CNNVD-202109-1676]

°²È«ÀàÐÍ£º

Îļþ¶ÁÈ¡

ÊÂÎñÃèÊö:

ApacheDruidÊÇÒ»¸öʵʱ³½ÎöÐÍÊý¾Ý¿â £¬Ö¼ÔÚ¶Ô´óÐÍÊý¾Ý¼¯½øÐм±¾çµÄ²éÎÊ·ÖÎö¡£ÔÚApacheDruidϵͳÖÐ £¬InputSourceÓÃÓÚ´Óij¸öÊý¾ÝÔ´¶ÁÈ¡Êý¾Ý¡£ÓÉÓÚûÓжÔÓû§¿É¿ØµÄHTTPInputSource×öÏÞ¶È £¬ApacheDruidÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§ÒÔDruid·þÎñÆ÷¹ý³ÌµÄȨÏÞ´ÓÖ¸¶¨Êý¾ÝÔ´¶ÁÈ¡Êý¾Ý £¬Ô̺¬±¾µØÎļþϵͳ¡£¹¥»÷Õß¿Éͨ¹ý½«ÎļþURL´«µÝ¸øHTTPInputSourceÀ´ÈƹýÀûÓ÷¨Ê½¼¶´ËÍâÏÞ¶È¡£ÓÉÓÚApacheDruidĬÈÏÇé¿öϲ»×ãÊÚȨÈÏÖ¤ £¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâÒªÇó £¬ÔÚδÊÚȨÇé¿öÏÂÀûÓø÷ì϶¶ÁÈ¡ËÁÒâÎļþ £¬×îÖÕµ¼Ö·þÎñÆ÷Ãô¸ÐÐÅϢй¶¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_WordPress_δÊÚȨ½Ó¼û[CVE-2019-17671][CNNVD-201910-1180]

°²È«ÀàÐÍ£º

·ÇÊÚȨ½Ó¼û/ȨÏÞÈÆ¹ý

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÀûÓÃWordPress5.2.3ÒÔǰµÄ·ì϶ £¬½øÐÐδÊÚȨµÄ°ÂÃØÎļþ½Ó¼û

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ǰ̨ËÁÒâÓû§ÃÜÂëÅú¸Ä·ì϶

°²È«ÀàÐÍ£º

Âß¼­/Éè¼ÆÃýÎó

ÊÂÎñÃèÊö:

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DedeCMSÔÚÓû§ÃÜÂë³ÁÖÃÖ°ÄÜ´¦ £¬php´æÔÚÈõÀàÐͱÈÁ¦ £¬µ¼ÖÂÈôÊÇÓû§Ã»ÓÐÉèÖÃÃܱ£ÎÊÌâµÄÇé¿öÏ £¬¹¥»÷ÕßÄܹ»ÈƹýÑéÖ¤Ãܱ£ÎÊÌâ £¬Ö±½ÓÅú¸ÄÃÜÂë(ÖÎÀíÔ¹ØË»§Ä¬Èϲ»ÉèÖÃÃܱ£ÎÊÌâ)¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMS_ǰ̨ÎļþÉÏ´«·ì϶

°²È«ÀàÐÍ£º

ÎļþÉÏ´«

ÊÂÎñÃèÊö:

DedeCmsÊÇÃâ·ÑµÄPHPÍøÕ¾ÄÚÈÝÖÎÀíϵͳ¡£DedeCmsÔÚÓû§°ä²¼ÎÄÕÂÉÏ´«Í¼Æ¬´¦´æÔÚÎļþÉÏ´«·ì϶ £¬¸Ã·ì϶ԴÓÚ¶ÔÉÏ´«Îļþºó׺¼ì²â²»ÑϽ÷ £¬¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ½ÚÔìÖ÷»ú¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Phpcms_install.php_ǰ̨Getshell

°²È«ÀàÐÍ£º

ÅäÖò»µ±/ÃýÎó

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ip¿ÉÄÜ´æÔÚÔÚÀûÓÃÖ÷ÕÅipµÄPhpcmsÉÏδɾ³ýµÄinstall.php½øÐжñÒâ¹¥»÷µÄÐÐΪ £¬Ä¿Ç°¹æ¶¨ÎÞ·¨ÕýÈ·ÅжÏÊÇ·ñΪ¶ñÒâ¹¥»÷¡£PHPCMSÊÇ¿ªÔ´µÄÕûվϵͳ¡£PHPCMS´æÔÚPHPCMS_v2008_preview.php×¢Èë·ì϶ £¬¹¥»÷ÕßÀûÓô˷ì϶ÇÔÈ¡Ãô¸ÐÐÅÏ¢ £¬»ñÈ¡Êý¾Ý¿âºÍÖÎÀíԱȨÏÞ¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ADSelfService-PlusδÊÚȨ_ËÁÒâ´úÂëÖ´ÐÐ[CVE-2021-40539][CNNVD-202109-330]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö:

ZOHOManageEngineADSelfServicePlusÊÇÃÀ¹ú׿ºÀ£¨ZOHO£©¹«Ë¾µÄÕë¶ÔActiveDirectoryºÍÔÆÀûÓ÷¨Ê½µÄ¼¯³Éʽ×ÔÖ÷ÃÜÂëÖÎÀíºÍµ¥µãµÇ¼½â¾ö¹æ»®¡£ZohoManageEngineADSelfServicePlus6113°æ±¾¼°¸üÔç°æ±¾´æÔÚÊÚȨÎÊÌâ·ì϶ £¬¸Ã·ì϶ԴÓÚÈí¼þºÜÈÝÒ×ÈÆ¹ýRESTAPIÈÏÖ¤ £¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_Spring-api-actuatorÓйØÎļþ_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

SpringBoot¹Ù·½ÌṩÁËspring-boot-starter-actuator³¡¾°Æô¶¯Æ÷ÓÃÓÚϵͳµÄ¼à¿ØÖÎÀí £¬Äܹ»Í¨¹ýHTTP £¬JMX £¬SSHºÍ̸À´½øÐвÙ×÷ £¬×Ô¶¯µÃµ½É󼯡¢½¡È«¼°Ö¸±êÐÅÏ¢µÈ¡£ÓйØÎļþ½ÔΪÃô¸ÐÎļþ £¬Î´×ö½Ó¼ûȨÏÞ½ÚÔ콫µ¼ÖÂÐÅϢй¶¡£

¸üй¦·ò£º

20211228


ÊÂÎñÃû³Æ£º

HTTP_Swagger-api¹¤¾ß_Ãô¸ÐÎļþ½Ó¼û

°²È«ÀàÐÍ£º

Ãô¸ÐÐÅϢй¶

ÊÂÎñÃèÊö:

SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢»ùÓÚYAML¡¢JSON˵»°µÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£© £¬ÓйØÎļþ¼Ð±»½Ó¼ûÓÐÐÅϢй¶·çÏÕ¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Seowon-Intech-SWC-9100-Routers_ºÅÁîÖ´ÐÐ[CVE-2013-7179][CNNVD-201402-022]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

SeowonIntechSWC-9100RoutersÊǺ«¹úÈðÔªÒóÌØ£¨SeowonIntech£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£SeowonIntechSWC-9100·ÓÉÆ÷ÖеÄcgi-bin/diagnostic.cgiÎļþÖеÄpingÖ°ÄÜÖдæÔÚÊäÈëÑéÖ¤·ì϶¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú¡®ping_ipaddr¡¯²ÎÊýÖеÄshellÔª×Ö·ûÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÖ÷ÓòÃû½âÎöÒªÇó7

°²È«ÀàÐÍ£º

ÍÚ¿óÈí¼þ

ÊÂÎñÃèÊö:

¼ì²âµ½¿ÉÒÉÍÚ¿óľÂíÊÔͼÏνÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂí³¢ÊÔÏνӿó³Ø £¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý £¬¿÷ËðCPU×ÊÔ´¡£ÈôÊÇΪÓû§Õý³£½Ó¼û¿ó³ØÖ÷Ò³ £¬ÔòºöÂÔ¸ÃÊÂÎñ¡£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_MicrosoftOffice_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-40444][CVE-2021-40444][CNNVD-202109-350]

°²È«ÀàÐÍ£º

ÎļþÏÂÔØ

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipµØµãµÄÖ÷»úÔÚÀûÓÃCVE-2021-40444ÏÂÔØ¶ñÒⷨʽ £¬ÊÂÎñ¼ì²âÏìÓ¦°üÌØµã¡£CVE-2021-40444ÊÇÒ»¸öÔÚ2021Äê9Ô±»±¬³öµÄÔÚÒ°ÀûÓõķì϶ £¬Óû§Ö»±ØÒªË«»÷Ö´ÐÐdocxÎļþ»òʹÓÃie½Ó¼û¶ñÒâÍøÕ¾ £¬¼´¿ÉÖ´ÐжñÒⷨʽ¡£¸Ã·ì϶λÓÚWindowsµÄMSHML×é¼þ £¬MSHML×é¼þÊÇ΢ÈíIEä¯ÀÀÆ÷µÄÅŰæÒýÇæ £¬Ò²Äܹ»ÔÚoffice·¨Ê½ÖгöÏÖwebÒ³Ãæ¡£MSHTMLÌṩÁËCOM½Ó¿Ú £¬ÈκÎÖ§³ÖCOMµÄ»·¾³¶¼Äܹ»Í¨¹ý¸Ã×é¼þ½Ó¼û¡¢±à×ëÍøÒ³¡£

¸üй¦·ò£º

20211228


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â £¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´® £¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê± £¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬´ËÐÐΪӵÓп϶¨·çÏÕ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬ÈçÈÆ¹ýWAF¼ì²â £¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓá£

¸üй¦·ò£º

20211228

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö:

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â £¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´® £¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê± £¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬´ËÐÐΪӵÓп϶¨·çÏÕ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬ÈçÈÆ¹ýWAF¼ì²â £¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓá£

¸üй¦·ò£º

20211228