Firefox´¹Î£½¨¸´RCE 0day£¨CVE-2019-11707£©£» £»£»£» £»TP-Link Wi-FiÖÐ¼ÌÆ÷RCE·ì϶

°ä²¼¹¦·ò 2019-06-19

¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190619



1¡¢Firefox´¹Î£½¨¸´RCE 0day£¨CVE-2019-11707£©

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
Mozilla°ä²¼Firefox 67.0.3ºÍFirefox ESR 60.7.1£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ´¹Î£½¨¸´¿Éµ¼ÖÂRCEµÄ0day£¨CVE-2019-11707£©¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶ÓÉGoogle Project ZeroÍŶӷ¢ÏÖ²¢»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»¸öÀàÐÍ»ìºÏ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬·ì϶±íÊöΪ£ºÓÉÓÚArray.popÖеÄÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬²Ù×÷JavaScript¶ÔÏóʱ¿ÉÄܻᴥ·¢·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¿ÉÀûÓõıÀÀ£¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶ÒÑÔÚÒ°±í±»ÀûÓ㬣¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/mozilla-firefox-6703-patches-actively-exploited-zero-day/


2¡¢TP-Link Wi-FiÖÐ¼ÌÆ÷RCE·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ó°Ïì¶à¸öÐͺÅ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
IBM X-Force×êÑÐÔ±Grzegorz WypychmembersÅû¶TP-Link Wi-Fi Extender£¨ÖÐ¼ÌÆ÷£©ÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£ ¡£¡£¡£¸Ã·ì϶ӰÏìÁ˲úÆ·ÐͺÅRE365¡¢RE650¡¢RE350ºÍRE500£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ¹Ì¼þ°æ±¾ÊÇ1.0.2£¬£¬£¬£¬£¬£¬£¬£¬buildΪ20180213¡£¡£¡£ ¡£¡£¡£TP-Link Wi-FiÖÐ¼ÌÆ÷ÔÚMIPS¼Ü¹¹ÉÏÔËÐУ¬£¬£¬£¬£¬£¬£¬£¬ÔÚ·¢ËÍÉ豸ÀûÓúÍÔËÐÐshellºÅÁîµÄÒªÇóʱ£¬£¬£¬£¬£¬£¬£¬£¬¿Éͨ¹ý´Û¸ÄHTTPÍ·ÖеÄuser agent×ֶδ¥·¢·ì϶£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓлúÓö½Ù³ÖÉ豸²¢»ñµÃÆëÈ«½ÚÔìȨ¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/critical-remote-execution-flaw-lurks-in-tp-link-wi-fi-extenders/


3¡¢Facebook WordPress²å¼þÁ½¸öCSRF 0day£¬£¬£¬£¬£¬£¬£¬£¬PoCÒѰ䲼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
Plugin Vulnerabilities×êÑÐÈËÔ±Åû¶Facebook WordPress²å¼þÖеÄÁ½¸öCSRF 0day¡£¡£¡£ ¡£¡£¡£ÊÜÓ°ÏìµÄÁ½¸ö²å¼þ±ðÀëÊÇMessenger Customer ChatºÍFacebook for WooCommerce£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐǰÕßÔÚ³¬¹ý2Íò¸öÕ¾µãÉÏ×°Ö㬣¬£¬£¬£¬£¬£¬£¬ºóÕßµÄ×°ÖÃÁ¿³¬¹ý20Íò´Î¡£¡£¡£ ¡£¡£¡£·ì϶ÔÊÐí¾­¹ýÉí·ÝÑéÖ¤µÄÓû§¸ü¸ÄWordPressÕ¾µãµÄÅäÖÃÑ¡Ï£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒѾ­°ä²¼ÁËÓйØÏ¸½ÚºÍPoC´úÂë¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/researchers-disclose-two-zero-day-vulnerabilities-impacting-two-facebook-wordpress-plugins-c304d71c


4¡¢Çóְƽ̨TalantonÒâ±íй¶½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
SafetyDetective×êÑÐÈËÔ±·¢ÏÖÒ»¸öÎÞ±£» £»£»£» £»¤µÄÊý¾Ý¿âй¶´óÁ¿¹ÍÖ÷ºÍÇóÖ°ÕßµÄÓ×ÎÒÐÅÏ¢¡£¡£¡£ ¡£¡£¡£¸ÃÊý¾Ý¿âÊôÓÚÓ¡¶ÈÇóְƽ̨Talanton£¬£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖж³öÁËÀ´×ÔÃÀ¹ú¡¢Ó¡¶È¡¢Ó¢¹ú¡¢°Ä´óÀûÑǵȹú¶ÈµÄ½ü160Íò¹ÍÖ÷ºÍÇóÖ°ÕßµÄÓ×ÎÒÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Èçµç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢¹ú¼®¡¢ÐÔ±ð¡¢×¡Ö·¡¢µ±Ç°¹ÍÖ÷¡¢¹¤×ÊÔ¤ÆÚ¡¢ÇóÖú״̬µÈ¡£¡£¡£ ¡£¡£¡£¸ÃÊý¾Ý¿â»¹Ô̺¬³¬¹ý5Íò¸ö¼ÓÃÜÃÜÂë¡£¡£¡£ ¡£¡£¡£Êý¾Ý¿âÓÚ5ÔÂ17ÈÕÖÁ6ÔÂ15ÈÕÖ®¼ä¶³ö£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ½Óµ½»ã±¨ºó£¬£¬£¬£¬£¬£¬£¬£¬ÍйܷþÎñÉÌTata Communications½«¸ÃÊý¾Ý¿âÍÑ»ú¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/job-searching-platform-exposes-personal-information-of-16-million-employers-and-job-seekers-6faf633f


5¡¢X Social Media¹«Ë¾Òâ±íй¶15Íò·ÝÖÐÉËË÷Åâ¼Í¼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
°²È«×êÑÐÈËÔ±Noam RotemºÍRan Locar·¢ÏÖ¸æ°×¹«Ë¾X Social MediaµÄÒ»¸öÎÞ±£» £»£»£» £»¤µÄÊý¾Ý¿âй¶ÁË15Íò·ÝÖÐÉËË÷Åâ¼Í¼¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾Ô®ÊÖÂÉʦÊÂÎñËùÓëÊܺ¦ÕßÇ©¶¨ºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âй¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂëÒÔ¼°±äÂÒ¡¢ÖÐÉË»ò¼²²¡Çé¿öµÄÚ¹ÊÍ£¬£¬£¬£¬£¬£¬£¬£¬»¹Ô̺¬Ó×ÎÒ½¡È«ÐÅÏ¢¡¢Ò½ÁÆÐÅÏ¢¡¢Ò½ÖÎϸ½ÚµÈ¡£¡£¡£ ¡£¡£¡£¸ÃÊý¾Ý¿â»¹Ô̺¬300¶à¼ÒÂÉʦÊÂÎñËùÏò¸æ°×¹«Ë¾Ö§¸¶µÄ¾ßÌåÓöÈÇåµ¥¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-database-belonging-to-an-ad-agency-has-exposed-150000-records-of-injury-claims-b1e38d28


6¡¢EatStreetÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬³¬¹ý600ÍòÌõÓû§¼Í¼±»ÇÔ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website
 
ʳƷ¶©¹º·þÎñ¹«Ë¾EatstreetÈ·ÈÏÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬¿Í»§¼°ºÏ×÷ͬ°éµÄ¾ßÌåÐÅÏ¢±»ÇÔ¡£¡£¡£ ¡£¡£¡£Æ¾¾ÝEatStreetµÄ±íÊö£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÓÚ5ÔÂ3ÈÕÈëÇÔìäÍÆËã»úÍøÂç²¢½Ó¼ûºÍÏÂÔØÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ö±ÖÁ5ÔÂ17Èոù«Ë¾¼ì²âµ½ÈëÇÖ²¢×èÖ¹ºÚ¿ÍµÄ½Ó¼û¡£¡£¡£ ¡£¡£¡£ºÚ¿ÍÇÔÈ¡µÄÐÅÏ¢Ô̺¬¶©¹ºÊ³Æ·µÄ¿Í»§ÐÅÏ¢¼°µÚÈý·½ËÍ»õ·þÎñµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÈçÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢ÒøÐÐÕË»§µÈ£¬£¬£¬£¬£¬£¬£¬£¬Óû§µÄÐÅÓþ¿¨Ö§¸¶¾ßÌåÐÅÏ¢Ò²Ôâй¶¡£¡£¡£ ¡£¡£¡£¸Ã¹«Ë¾²¢Î´Ð¹Â©Óм¸¶àÓû§Êܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬µ«ºÚ¿ÍÐû³Æ¹²ÇÔÈ¡ÁË600¶àÍòÌõÓû§¼Í¼¡£¡£¡£ ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/eatstreet-food-ordering-service-discloses-security-breach/