2020-11-10

Ðû²¼Ê±¼ä 2020-11-10
ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Downloader.APT-C-23_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ APT-C-23ÏÂÔØÆ÷ľÂí ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË APT-C-23ÏÂÔØÆ÷ľÂí¡£¡£¡£APT-C-23ÏÂÔØÆ÷ľÂí ÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Nagios_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-20197]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

NagiosÊÇÒ»¿î¿ªÔ´µÄµçÄÔϵͳºÍÍøÂç¼àÊÓ¹¤¾ß£¬£¬£¬£¬£¬£¬ÄÜÓÐÓÃ¼à¿ØWindows¡¢LinuxºÍUnixµÄÖ÷»ú״̬£¬£¬£¬£¬£¬£¬½»Á÷»ú·ÓÉÆ÷µÈÍøÂçÉèÖ㬣¬£¬£¬£¬£¬´òÓ¡»úµÈ¡£¡£¡£ÔÚϵͳ»òЧÀÍ״̬Ò쳣ʱ·¢³öÓʼþ»ò¶ÌÐű¨¾¯µÚһʱ¼äÍ¨ÖªÍøÕ¾ÔËάְԱ£¬£¬£¬£¬£¬£¬ÔÚ״̬»Ö¸´ºó·¢³öÕý³£µÄÓʼþ»ò¶ÌÐÅ֪ͨ¡£¡£¡£ÔÚNagios XI 5.6.9°æ±¾ÖУ¬£¬£¬£¬£¬£¬NagiosµÄ¡°±¨¸æ¡±Ä£¿£¿£¿£¿ £¿£¿é±£´æÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâµÄ²Ù×÷ϵͳÏÂÁî¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Nodejs´úÂë×¢ÈëÎó²î[CVE-2020-7699][CNNVD-202007-1739]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¸ÃÎó²îλÓÚexpress-fileupload npm×é¼þÖУ¬£¬£¬£¬£¬£¬¸Ã×é¼þ´Ónpm´¦ÏÂÔØÁ¿Áè¼Ý730Íò£¬£¬£¬£¬£¬£¬ÆäÖв»º¬ÓдÓGitHub¡¢¾µÏñÍøÕ¾ºÍÆäËû¿Ë¡¿âÖÐÏÂÔØµÄ¡£¡£¡£¸ÃÎó²îÊôÓÚPrototype Pollution£¨Ô­ÐÍÎÛȾ£©Îó²îÀàÐÍ£¬£¬£¬£¬£¬£¬ÕâÊÇJS´úÂëÖеij£¼ûÎó²îÀàÐÍ¡£¡£¡£ÓÉÓÚJSÊÇ»ùÓÚÔ­Ð͵ÄÓïÑÔ£¬£¬£¬£¬£¬£¬ÓïÑÔÖеÄÿ¸ö¹¤¾ß¡¢º¯ÊýºÍÊý¾Ý½á¹¹¶¼ÓÐPrototypeÌØÕ÷£¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý"_proto__"¾ÙÐÐÐ޸ġ£¡£¡£Ê¹ÓÃÕâÖÖÉè¼ÆÎó²îµÄÔ­Ð͹¥»÷ͨ¹ý×¢Èë²»Ïà˳ӦµÄ¹¤¾ßÀàÐ͵½ÏÖÓеŤ¾ßÖÐÀ´Òý·¢¹ýʧ£¬£¬£¬£¬£¬£¬ÆæÈȵ¼ÖÂDoS¹¥»÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ApacheKylin_ÏÂÁî×¢ÈëÎó²î[CVE-2020-1956][CNNVD-202005-1133]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Apache Kylin ÊÇÃÀ¹úApache Èí¼þ»ù½ð»áµÄÒ»¿î¿ªÔ´µÄÂþÑÜʽÆÊÎöÐÍÊý¾Ý¿ÍÕ»¡£¡£¡£¸Ã²úÆ·Ö÷ÒªÌṩ Hadoop/Spark Ö®É쵀 SQL ÅÌÎʽӿڼ°¶àάÆÊÎö£¨OLAP£©µÈ¹¦Ð§¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_XXL_JOB_δÊÚȨ»á¼ûÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XXL-JOBÊÇÒ»¸öÇáÁ¿¼¶ÂþÑÜʽʹÃüµ÷ÀíÆ½Ì¨¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂXXL-JOBµÄRestful API½Ó¿Ú»òRPC½Ó¿ÚûÓÐÉèÖÃÈÏÖ¤²½·¥£¬£¬£¬£¬£¬£¬Î´ÊÚȨµÄ¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬Ôì³ÉÔ¶³ÌÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬Ö±½Ó¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Oracle_Weblogic_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-14882][CVE-2020-14750]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܽÓÊÜOracle WebLogic Server¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÊÂÎñÃû³Æ£º

HTTP_WebLogic_XXE×¢ÈëÎó²î[CVE-2019-2887]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWebLogic_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£WebLogic_XXE×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ýT3ЭÒé¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷,í§ÒâÎļþ¶ÁÈ¡£¬£¬£¬£¬£¬£¬»ñÈ¡ÍøÕ¾µÄÃô¸ÐÊý¾ÝµÈ¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÊÂÎñÃû³Æ£º

HTTP_WebLogic_Blind_XXE×¢ÈëÎó²î[CVE-2019-2647]

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWebLogic_Blind_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£WebLogic_Blind_XXE×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬£¬£¬£¬£¬£¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110


ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£

¸üÐÂʱ¼ä£º

20201110