ÿÖÜÉý¼¶²¼¸æ-2022-12-27

°ä²¼¹¦·ò 2022-12-27
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Cacti_ºÅÁîÖ´ÐÐ[CVE-2022-46169][CVE-2022-46169]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

CactiÏîÄ¿ÊÇÒ»¸ö¿ªÔ´Æ½Ì¨£¬£¬£¬£¬ £¬£¬ £¬ £¬¿ÉΪÓû§Ìṩ׳´óÇÒ¿ÉÀ©´óµÄ²Ù×÷¼à¿ØºÍ¹ÊÕÏÖÎÀí¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚremote_agent.phpÖеÄcasePOLLER_ACTION_SCRIPT_PHPÔÚʹÓÃproc_openº¯Êýʱδ¶Ô´«ÈëµÄpoller_id²ÎÊý×öÑϸñ¹ýÂË£¬£¬£¬£¬ £¬£¬ £¬ £¬¹¥»÷Õ߿ɻú¹ØÂú×ãǰÌáµÄpayload¶ÔÓйØÖ¸±êϵͳ½øÐкÅÁî×¢È룬£¬£¬£¬ £¬£¬ £¬ £¬µ¼ÖÂÔ¶³ÌºÅÁîÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£Ó°ÏìÁìÓò£ºCacti==1.2.22

¸üй¦·ò£º

20221227

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Hessain_lite_´úÂëÖ´ÐÐ[CVE-2022-39198]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

HessianÊÇÒ»ÖÖ¶¯Ì¬ÀàÐ͵Ķþ½øÔìÐòÁл¯ºÍWeb·þÎñºÍ̸£¬£¬£¬£¬ £¬£¬ £¬ £¬×¨ÎªÃæÏò¶ÔÏóµÄ´«Êä¶øÉè¼Æ¡£¡£¡£¡£¡£¡£¡£¡£Hessian-lite×î³õÊǹٷ½hessianµÄApachedubboembed°æ±¾£¬£¬£¬£¬ £¬£¬ £¬ £¬Õâ¸öÄ£¿£¿£¿£¿£¿ £¿éºóÀ´´ÓDubboÖзÖÀë³öÀ´¡£¡£¡£¡£¡£¡£¡£¡£DubboµÄËùÓзÖÖ§£º2.5.x¡¢2.6.x(×Ô2.6.3)ºÍ2.7.x¶¼ÒÀÀµÓÚËü¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚHessian-liteÔÚ½øÐÐÐòÁл¯Êý¾Ý´«Êäʱ´æÔÚ·ì϶£¬£¬£¬£¬ £¬£¬ £¬ £¬¹¥»÷Õß¿Éͨ¹ý¾«ÐĹ¹½¨µÄpayloadÈÆ¹ý¹Ù·½µÄºÚÃûµ¥ÀàÏÞ¶È£¬£¬£¬£¬ £¬£¬ £¬ £¬´Ó¶øÔÚÖ¸±êÖ÷»úÉÏÔì³ÉÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20221227

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ThinkPhp_lang_pearcmd_ÎļþÔ̺¬[CVE-2022-47945]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃThinkphp¶à˵»°Ö°ÄÜÖдæÔÚµÄĿ¼´©Ô½½øÐÐÎļþÔ̺¬¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ThinkPHPÊÇÒ»¸öÔÚÖйúʹÓý϶àµÄPHP¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÆä6.0.13°æ±¾¼°ÒÔǰ£¬£¬£¬£¬ £¬£¬ £¬ £¬´æÔÚÒ»´¦±¾µØÎļþÔ̺¬·ì϶¡£¡£¡£¡£¡£¡£¡£¡£µ±¶à˵»°¸öÐÔ±»¿ªÆôʱ£¬£¬£¬£¬ £¬£¬ £¬ £¬¹¥»÷ÕßÄܹ»Ê¹ÓÃlang²ÎÊýÀ´Ô̺¬ËÁÒâPHPÎļþ£¬£¬£¬£¬ £¬£¬ £¬ £¬²¢½øÒ»²½Í¨¹ýpearcmd.phpʵÏÖËÁÒâÎļþдÈë¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20221227

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_fuelCMS_1.4.1_´úÂëÖ´ÐÐ[CVE-2018-16763]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

FUELCMSÊÇÒ»¿î»ùÓÚCodeIgniterµÄÄÚÈÝÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Æä1.4.1°æ±¾´æÔÚ·ì϶£¬£¬£¬£¬ £¬£¬ £¬ £¬ÔÊÐíͨ¹ýpages/select/Ö´ÐÐphp´úÂ룬£¬£¬£¬ £¬£¬ £¬ £¬Õâ¿ÉÄܻᵼÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20221227

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_DrayTek_Ô¤Éí·ÝÑéÖ¤_ºÅÁîÖ´ÐÐ[CVE-2020-8515]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½¹¥»÷ÕßÀûÓÃDrayTekÔ¤Éí·ÝÑéÖ¤´¦µÄÁ½´¦ºÅÁî×¢Èë·ì϶½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£DrayTekÊÇÒ»¼ÒÔÚÖйú³ö²ú·À»ðǽ£¬£¬£¬£¬ £¬£¬ £¬ £¬VPNÉ豸£¬£¬£¬£¬ £¬£¬ £¬ £¬Â·ÓÉÆ÷£¬£¬£¬£¬ £¬£¬ £¬ £¬WLANÉ豸µÈµÄÔì×÷ÉÌ¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ/cgi-bin/mainfunction.cgi·¨Ê½Î´ÕýÈ·¹ýÂËkeyPath×ֶκÍrtick×Ö¶ÎÆäÖеÄÌØÊâ×Ö·û£¬£¬£¬£¬ £¬£¬ £¬ £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶²»¾­¹ýÉí·ÝÑéÖ¤ÒÔrootȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬£¬ £¬£¬ £¬ £¬Äܹ»rootȨÏÞÖ´ÐдúÂë

¸üй¦·ò£º

20221227

 

ÊÂÎñÃû³Æ£º

TCP_Éó¼ÆÊÂÎñ_java.lang.ProcessBuilder_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´Ö¸±êIPÔÚʹÓÃJava¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚJavaÖУ¬£¬£¬£¬ £¬£¬ £¬ £¬·¨Ê½¿ª·¢ÈËԱͨ³£»£»£»£»£»áͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½Ö´ÐÐ±í²¿µÄShellºÅÁî¡£¡£¡£¡£¡£¡£¡£¡£ProcessBuilderÊÇjava5.0ÒýÈëµÄ£¬£¬£¬£¬ £¬£¬ £¬ £¬start()²½Öè·µ»ØProcessµÄÒ»¸öÊ·ý¡£¡£¡£¡£¡£¡£¡£¡£Í¨³£ÔÚJavaÓйصÄÀûÓÃϵͳÖУ¬£¬£¬£¬ £¬£¬ £¬ £¬ÈôÊÇ´¦ÖÃ±í²¿ºÅÁîÖ´ÐÐʱ£¬£¬£¬£¬ £¬£¬ £¬ £¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË£¬£¬£¬£¬ £¬£¬ £¬ £¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâ¸ö·ì϶Զ³Ì×¢ÈëºÅÁî»ò´úÂë²¢Ö´ÐÓ×£¡£¡£¡£¡£¡£¡£¡£ÖîÈçStruts2¡¢SpringÕâЩÀûÓÃÒѾ­±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬ £¬£¬ £¬ £¬ÀýÈçOgnl±í°×ʽºÍSpEL±í°×ʽµÄËÁÒâ´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý¶¯Ì¬Å²ÓÃjava.lang.ProcessBuilder·½Ê½ÔÚ³öȱµãÀûÓÃÖÐÖ´ÐÐËÁÒâ´úÂë»òºÅÁ£¬£¬£¬ £¬£¬ £¬ £¬½øÒ»²½ÆëÈ«½ÚÔìÖ¸±ê·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£³¢ÊÔÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20221227

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ThinkPhp_lang_ÎļþÔ̺¬[CVE-2022-47945]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃThinkphp¶à˵»°Ö°ÄÜÖдæÔÚµÄĿ¼´©Ô½½øÐÐÎļþÔ̺¬¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£hinkPHPÊÇÒ»¸öÔÚÖйúʹÓý϶àµÄPHP¿ò¼Ü¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÆä6.0.13°æ±¾¼°ÒÔǰ£¬£¬£¬£¬ £¬£¬ £¬ £¬´æÔÚÒ»´¦±¾µØÎļþÔ̺¬·ì϶¡£¡£¡£¡£¡£¡£¡£¡£µ±¶à˵»°¸öÐÔ±»¿ªÆôʱ£¬£¬£¬£¬ £¬£¬ £¬ £¬¹¥»÷ÕßÄܹ»Ê¹ÓÃlang²ÎÊýÀ´Ô̺¬ËÁÒâPHPÎļþ¡£¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20221227