ÿÖÜÉý¼¶²¼¸æ-2021-05-04
°ä²¼¹¦·ò 2021-05-06ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Seowon-SlC-130-Router_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-17456] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Ö÷»úÔÚÔâ·êSeowon-SlC-130-Router_Ô¶³Ì´úÂëÖ´Ðй¥»÷·ì϶±àºÅ:CVE-2020-17456Ó°ÏìÉ豸:SlC-130¡¢SLR-120S·ì϶·çÏÕˮƽ:Äܹ»»ñÈ¡µ½É豸µÄshell£¬£¬£¬£¬£¬£¬²¢ÇÒÊÇÒÔrootȨÏÞ¡£¡£¡£¡£¡£¡£·ì϶²úÉúµÄµØÎ»:²úÉúµÄµØÎ»ÔÚ²âÊÔÍøÂçÁªÍ¨µÄ´¦Ëù£¬£¬£¬£¬£¬£¬Ò²¾ÍÊÇpingµÄµØÖ·£¬£¬£¬£¬£¬£¬Õâ¸ö´¦ËùÄܹ»±»Èƹý¾¹ýÒÔǰ¶Ô·ÓÉÆ÷·ì϶µÄ×êÑУ¬£¬£¬£¬£¬£¬²»ÉٵķÓÉÆ÷·ì϶²úÉúµã¶¼ÔÚÕâ¸ö²¿ÃÅ¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ª·¢ÈËÔ±¶ÔÊäÈëµÄ²ÎÊýûÓнøÐÐÓÐЧµÄÑéÖ¤ºÍ·¸·¨×Ö·û¹ýÂË¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_F5-BIG-IP_/mgmt/tm/access/bundle-install-tasks´¦_Ô¶³Ì´úÂë·ì϶[CVE-2021-22986][CNNVD-202103-770] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | µ±Ç°Ö÷»úÔÚÔâ·êF5-BIG-IP_Ô¶³Ì´úÂë·ì϶¹¥»÷¡£¡£¡£¡£¡£¡£BIG-IP´æÔÚ´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐí½ç˵Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýBIG-IPÖÎÀí½çÃæºÍ×ÔÉíIPµØÖ·¶ÔiControlREST½Ó¿Ú½øÐÐÍøÂç½Ó¼û£¬£¬£¬£¬£¬£¬ÒÔÖ´ÐÐËÁÒâϵͳºÅÁ£¬£¬£¬£¬£¬´´½¨»òɾ³ýÎļþÒÔ¼°´úÌæ·þÎñ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ֻÄÜͨ¹ý½ÚÔì½çÃæÀûÓ㬣¬£¬£¬£¬£¬¶ø²»ÄÜͨ¹ýÊý¾Ý½çÃæÀûÓᣡ£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_IIS½âÎö·ì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½ÀûÓÃIISÎļþÃûºó׺½âÎöÃýÎóµÄÉÏ´«ÐÐΪµ±ÊÔͼ³¢ÊÔ»òÀûÓÃWEBÀûÓûò·þÎñÆ÷ƽ̨µÄMIME¼ì²â·ì϶ʱÊÂÎñ±»´¥·¢,¹¥»÷ÕßÄܹ»³¢ÊÔͨ¹ýÉÏ´«¸÷Àà¶ñÒâÎļþÀ´¹¥»÷Ö¸±êÖ÷»ú¡£¡£¡£¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |

ÊÂÎñÃû³Æ£º | HTTP_Nginx½âÎö·ì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½ÀûÓÃNginxÎļþÃûºó׺½âÎöÃýÎóµÄÉÏ´«ÐÐΪ¡£¡£¡£¡£¡£¡£nginxÊǶíÂÞ˹Èí¼þ¿ª·¢ÕßIgorSysoevËùÑз¢µÄÒ»¿îHTTPºÍ·´Ïò´úÀí·þÎñÆ÷£¬£¬£¬£¬£¬£¬Ò²Äܹ»×÷ΪÓʼþ´úÀí·þÎñÆ÷¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÑéÖ¤Ô̺¬Î´×ªÒå¿Õ¸ñ×Ö·ûµÄÒªÇóURI¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ìÏ¶ÈÆ¹ý¼È¶¨µÄÏÞ¶È¡£¡£¡£¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ÊÂÎñÃû³Æ£º | HTTP_Adobe_ColdFusion·´ÐòÁл¯·ì϶[CVE-2018-15958/15959][CNNVD-201809-488] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýAdobeColdFusion·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£¡£AdobeColdFusionµÄFlashGateway·þÎñ´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÏòÖ¸±êAdobeColdFusionµÄFlashGateway·þÎñ·¢Ë;«ÐÄ»ú¹ØµÄ¶ñÒâÊý¾Ý£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£·ì϶´æÔڵİ汾£ºAdobeColdFusion2016.0Update6AdobeColdFusion2016.0Update5AdobeColdFusion2016.0Update4AdobeColdFusion2016.0Update3AdobeColdFusion2016.0Update2AdobeColdFusion2016.0Update1AdobeColdFusion2018.0.0.310739AdobeColdFusion11Update9AdobeColdFusion11Update8AdobeColdFusion11Update7AdobeColdFusion11Update6AdobeColdFusion11Update5AdobeColdFusion11Update4AdobeColdFusion11Update3AdobeColdFusion11Update2AdobeColdFusion11Update14AdobeColdFusion11Update13AdobeColdFusion11Update12AdobeColdFusion11Update11AdobeColdFusion11Update10AdobeColdFusion11Update1³¢ÊÔÀûÓÃCVE-2018-15958AdobeColdFusion·´ÐòÁл¯·ì϶¹¥»÷¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ÊÂÎñÃû³Æ£º | HTTP_ThinkPHP5Ô¶³Ì´úÂëÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃThinkPHP¿ò¼ÜÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬£¬£¬£¬£¬£¬ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£¡£¡£¡£¡£¡£ThinkPHPÊÇÒ»¸öÊ¢ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£¡£¡£¡£¡£¡£µ±WebÍøÕ¾ÊÇ»ùÓÚThinkPHP¿ò¼Ü¿ª·¢Ê±£¬£¬£¬£¬£¬£¬¿ÉÄÜ´æÔڸ÷ì϶ʱ¡£¡£¡£¡£¡£¡£¹¥»÷Õß·¢Ë;«ÐÄ»ú¹ØµÄPHP´úÂëÔÚÖ¸±êÖ÷»úÉÏÖ´ÐУ¬£¬£¬£¬£¬£¬Ì°Í¼½øÒ»²½½ÚÔì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |

ÊÂÎñÃû³Æ£º | HTTP_Apache_Solr_Velocity_Ô¶³Ì´úÂëÖ´Ðзì϶_Config_API |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃApache_Solr_VelocityÔ¶³Ì´úÂëÖ´Ðзì϶_Config_API¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¹¥»÷³É¹¦£¬£¬£¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ÊÂÎñÃû³Æ£º | TCP_Java¾²Ì¬Å²ÓÃ_java.lang.Runtime_Ô¶³Ì´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´Ö¸±êIPÔÚʹÓÃJava¾²Ì¬Å²ÓÃjava.lang.Runtime·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ÔÚJavaÖУ¬£¬£¬£¬£¬£¬·¨Ê½¿ª·¢ÈËԱͨ³£»£»£»£»£»áͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½Ê½Ö´ÐÐ±í²¿µÄShellºÅÁî¡£¡£¡£¡£¡£¡£RuntimeÀàÊÇJava·¨Ê½µÄÔËÐÐʱ»·¾³£¬£¬£¬£¬£¬£¬¿ª·¢ÕßÄܹ»Í¨¹ýgetRuntime()²½Öè»ñÈ¡µ±Ç°RuntimeÔËÐÐʱ¶ÔÏóµÄÒýÓᣡ£¡£¡£¡£¡£Í¨³£ÔÚJavaÓйصÄÀûÓÃϵͳÖУ¬£¬£¬£¬£¬£¬ÈôÊÇ´¦ÖÃ±í²¿ºÅÁîÖ´ÐÐʱ£¬£¬£¬£¬£¬£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâ¸ö·ì϶Զ³Ì×¢ÈëºÅÁî»ò´úÂë²¢Ö´ÐС£¡£¡£¡£¡£¡£ÖîÈçStruts2¡¢SpringÕâЩÀûÓÃÒѾ±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬ÀýÈçOgnl±í°×ʽºÍSpEL±í°×ʽµÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¾²Ì¬Å²ÓÃjava.lang.Runtime·½Ê½ÔÚ³öȱµãÀûÓÃÖÐÖ´ÐÐËÁÒâ´úÂë»òºÅÁ£¬£¬£¬£¬£¬½øÒ»²½ÆëÈ«½ÚÔìÖ¸±ê·þÎñÆ÷¡£¡£¡£¡£¡£¡£³¢ÊÔÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ÊÂÎñÃû³Æ£º | HTTP_Àà²Ëµ¶Á÷Á¿_ÏìÓ¦ |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | Öйú²Ëµ¶ÊÇÖйúºÚ¿ÍȦÄÚʹÓü«¶È¿í·ºµÄÒ»¿îWebshellÖÎÀí¹¤¾ß¡£¡£¡£¡£¡£¡£Öйú²Ëµ¶Óô¦¼«¶È¿í·º,Ö§³Ö¶àÖÖ˵»°,Ó×ÇÉʵÓ㬣¬£¬£¬£¬£¬ÓµÓÐÎļþÖÎÀí£¨ÓÐ×ã¹»µÄȨÏÞʱ³½Äܹ»ÖÎÀíÕû¸ö´ÅÅÌ/Îļþϵͳ£©£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖÎÀí£¬£¬£¬£¬£¬£¬Ðé¹¹Öն˵ÈÖ°ÄÜ¡£¡£¡£¡£¡£¡£¶ÔÓÚÕâÀàÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬ÈôÊÇûÓдóÁ¿µÄÅú¸Ä·þÎñ¶Ë¾ç±¾´úÂ룬£¬£¬£¬£¬£¬Æä·µ»ØÁ÷Á¿³ÇÊÐÓÐһЩ³£¼ûµÄÌØµã£¬£¬£¬£¬£¬£¬±¾ÌõÎÄÔò½«³£¼ûµÄ¹²Í¬ÌصãÌáÈ¡³öÀ´½øÐзÀÓùÐÔ±¨¾¯¡£¡£¡£¡£¡£¡£ÓÉÓÚ´ËÊÂÎñΪ½ÏΪ¿í·ºµÄͨÓÃÌØµã£¬£¬£¬£¬£¬£¬¿ÉÄÜ´æÔÚÎ󱨣¬£¬£¬£¬£¬£¬Çë²Î¿¼ÌصãÐÔÖÊÅжÏ×ֶνøÐÐÅжϡ£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_WordPress_Easy_WP_SMTPÈÕÖ¾Îļþ̽²â |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²â¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃWordPressµÄEasy_WP_SMTP²å¼þÈÕ־¶³öÔÚ±í½øÐÐδÊÚȨ½Ó¼û¼°ÃÜÂë¶ñÒâÅú¸Ä£»£»£»£»£»EasyWPSMTPÔÊÐíÄúÅäÖúÍͨ¹ýSMTP·þÎñÆ÷·¢ËÍËùÓÐ±í·¢µç×ÓÓʼþ¡£¡£¡£¡£¡£¡£ÕâÑùÄܹ»Ô¤·ÀÄúµÄµç×ÓÓʼþ½øÈëÊÕ¼þÈ˵ÄÀ¬»øÓʼþÎļþ¼Ð¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_wget_curlÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐÐ |
°²È«ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÏòÖ÷ÕÅIPÖ÷»ú·¢ËÍ¿ÉÒɺÅÁ£¬£¬£¬£¬£¬³¢ÊÔ½ÚÔìÖ÷ÕÅIPÖ÷»úÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐС£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210504 |
ɾ³ýÊÂÎñ
1. HTTP_ľÂíºóÃÅ_webshell_AntSword_php½ÚÔìºÅÁî
2. TCP_±ùЫ_php_webshell_ÉÏ´«
3. TCP_RealVNC_RFBºÍ̸Զ³ÌÈÏÖ¤ÈÆ¹ý·ì϶[CVE-2006-2369]
4. HTTP_Citrix_ADC_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-8193][CNNVD-202007-367]
5. HTTP_°²È«·ì϶_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ


¾©¹«Íø°²±¸11010802024551ºÅ