¹¥»÷ÕßÀûÓÃGhost CMS¸ßΣ·ì϶עÈë¶ñÒâ´úÂë

°ä²¼¹¦·ò 2026-05-25

1. ¹¥»÷ÕßÀûÓÃGhost CMS¸ßΣ·ì϶עÈë¶ñÒâ´úÂë


5ÔÂ24ÈÕ£¬£¬ £¬ £¬£¬Ò»³¡´ó¹æÄ£ÍøÂç¹¥»÷»î¶¯ÕýÀûÓÃGhostÄÚÈÝÖÎÀíϵͳ£¨CMS£©ÖеÄÒ»¸öÑϳÁSQL×¢Èë·ì϶£¨CVE-2026-26980£©£¬£¬ £¬ £¬£¬ÏòÖ¸±êÍøÕ¾×¢Èë¶ñÒâJavaScript´úÂ룬£¬ £¬ £¬£¬½ø¶ø´¥·¢ClickFix¹¥»÷Á÷³Ì¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìGhost 3.24.0ÖÁ6.19.0°æ±¾£¬£¬ £¬ £¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß´ÓÍøÕ¾Êý¾Ý¿âÖжÁÈ¡ËÁÒâÊý¾Ý£¬£¬ £¬ £¬£¬Ô̺¬ÖÎÀíÔ±APIÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£Ò»µ©»ñµÃ¸ÃÃÜÔ¿£¬£¬ £¬ £¬£¬¹¥»÷Õß±ã¿ÉÕ¼ÓÐÖÎÀíԱȨÏÞ£¬£¬ £¬ £¬£¬½Ó¼ûÓû§¡¢ÎÄÕºÍÖ÷Ì⣬£¬ £¬ £¬£¬²¢´Û¸ÄÎÄÕÂÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜGhost CMSÒÑÔÚ6.19.1°æ±¾ÖÐÓÚ2ÔÂ19ÈÕ°ä²¼½¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬ £¬ £¬£¬µ«´óÁ¿ÍøÕ¾Î´ÄÜʵʱ¸üУ¬£¬ £¬ £¬£¬µ¼Ö·ì϶±»¿í·ºÀûÓᣡ£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬ £¬ £¬£¬Õâ´Î¹¥»÷ÒÑÓ°Ï쳬¹ý700¸öÓòÃû£¬£¬ £¬ £¬£¬Êܺ¦ÕßÔ̺¬´óѧÃÅ»§ÍøÕ¾¡¢ÈËΪÖÇÄÜÓëSaaS¹«Ë¾¡¢Ã½Ìå»ú¹¹¡¢½ðÈڿƼ¼¹«Ë¾¡¢°²È«ÍøÕ¾ÒÔ¼°Ó×ÎÒ²©¿Í¡£¡£¡£¡£¡£¡£¡£ÁîÈ˹Ø×¢µÄÊÇ£¬£¬ £¬ £¬£¬¹¥»÷ÕßÉõÖÁÔÚ¹þ·ð´óѧ¡¢Å£½ò´óѧ¡¢°Â±¾´óѧºÍDuckDuckGoµÈ³ÛÃû»ú¹¹µÄÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÖÁÉٹ۲쵽Á½¸ö·ÖÆçµÄ¹¥»÷»î¶¯¼¯Èº£¬£¬ £¬ £¬£¬ËüÃÇ»áÖØÎÂϰȾͳһÓòÃû£¬£¬ £¬ £¬£¬ÉõÖÁÔÚËãÕʺó³ÁÐÂ×¢Èë¾ç±¾£¬£¬ £¬ £¬£¬»òÕßÏ໥¸²¸Ç¶Ô·½µÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/


2. Laravel Lang°üÔâ´Û¸Ä£¬£¬ £¬ £¬£¬¹©¸øÁ´¹¥»÷ÇÔÈ¡¿ª·¢Õ߯¾Ö¤


5ÔÂ23ÈÕ£¬£¬ £¬ £¬£¬Ò»³¡Õë¶ÔLaravel Lang±¾µØ»¯°üµÄ¹©¸øÁ´¹¥»÷ÔÚ²úÉú£¬£¬ £¬ £¬£¬¹¥»÷Õßͨ¹ýÀÄÓÃGitHub°æ±¾±êǩְÄÜ£¬£¬ £¬ £¬£¬ÀûÓÃComposer°üÖÎÀíÆ÷·Ö·¢¶ñÒâ´úÂ룬£¬ £¬ £¬£¬Ê¹¿ª·¢ÕßÃæ¶Ô¸´Ôӵį¾Ö¤ÇÔÈ¡¶ñÒâÈí¼þÍþв¡£¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾StepSecurity¡¢Aikido SecurityºÍSocketÓÚ½üÈÕ·¢³öÖҸ棬£¬ £¬ £¬£¬³Æ¹¥»÷Õß´Û¸ÄÁËLaravel Lang×éÖ¯ÊØ»¤µÄËĸö´æ´¢¿âÖеÄGitHub±êÇ©£¬£¬ £¬ £¬£¬¶ø·Ç°ä²¼È«ÐµĶñÒâ°æ±¾¡£¡£¡£¡£¡£¡£¡£ÕâЩLaravel LangÈí¼þ°üÊǵÚÈý·½±¾µØ»¯°ü£¬£¬ £¬ £¬£¬²¢·ÇLaravel¹Ù·½ÏîÖ÷ÕÅÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÌØÊâÖ®´¦ÔÚÓÚ£¬£¬ £¬ £¬£¬¹¥»÷Õß²¢Ã»ÓÐÅú¸ÄÏîÖ÷ÕÅÏÖʵԴ´úÂëÀ´Ôö³¤¶ñÒâ´úÂ룬£¬ £¬ £¬£¬¶øÊÇÀÄÓÃÁËGitHubµÄÒ»ÏîÖ°ÄÜ£¬£¬ £¬ £¬£¬¸ÃÖ°ÄÜÔÊÐí±êǩָÏòͳһ´æ´¢¿âÖÐ·ÖÆç·ÖÖ§µÄÌá½»¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß³ÁдÁËÿ¸ö´æ´¢¿âÖÐËùÓÐÏÖÓеÄgit±êÇ©£¬£¬ £¬ £¬£¬Ê¹ÆäÖ¸ÏòÒ»¸öеĶñÒâÌá½»£¬£¬ £¬ £¬£¬¶ø·Ç°ä²¼ÐµĶñÒâ°æ±¾¡£¡£¡£¡£¡£¡£¡£³Áд²Ù×÷´Ólaravel-lang/langÆðÍ·£¬£¬ £¬ £¬£¬µ½laravel-lang/actionsʵÏÖ£¬£¬ £¬ £¬£¬ËùÓÐËĸö²Ö¿â¾ùʹÓÃÁËÒ»ÑùµÄα×ö×÷ÕßÉí·Ý¡¢Ò»ÑùµÄÅú¸ÄÎļþºÍÒ»ÑùµÄÓÐÐ§ÔØºÉÐÐΪ£¬£¬ £¬ £¬£¬ÕâÏÕЩÄܹ»×¢¶¨ÊÇÓÉͳһ¹¥»÷ÕßʹÓÃÒ»¸ö±»µÁÓõġ¢ÓµÓÐ×éÖ¯¼¶ÍÆËÍȨÏÞµÄÆ¾Ö¤ËùΪ¡£¡£¡£¡£¡£¡£¡£¾ÝAikido³Æ£¬£¬ £¬ £¬£¬¹¥»÷ÕßÈëÇÖÁËÈý¸ö´æ´¢¿âÖеÄ233¸ö°æ±¾£¬£¬ £¬ £¬£¬¶øSocket°µÊ¾Ô¼Äª700¸öº¹Çà°æ±¾¿ÉÄÜÊܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/laravel-lang-packages-hijacked-to-deploy-credential-stealing-malware/


3. Òâ´óÀû·ÛËéCINEMAGOALµÁ°æÉú̬£¬£¬ £¬ £¬£¬ÖÂ3ÒÚÅ·ÔªËðʧ


5ÔÂ23ÈÕ£¬£¬ £¬ £¬£¬Òâ´óÀûµÐÔֳɹ¦·ÛËéÁËÒ»¸öÒÔCINEMAGOALÀûÓÃΪÖ÷ÌâµÄÖØ´óµÁ°æÉú̬ϵͳ¡£¡£¡£¡£¡£¡£¡£ÓëµäÐ͵ÄIPTV·þÎñÌṩÉÌ·ÖÆç£¬£¬ £¬ £¬£¬CINEMAGOAL²ÉÈ¡Á˸üΪÒñ±ÎµÄÔË×÷·½Ê½£¬£¬ £¬ £¬£¬Ëü²»½øÐй«¿ªÓªÏú£¬£¬ £¬ £¬£¬¶øÊÇͨ¹ýÓû§×ÔÐÐ×°ÖõÄÀûÓ÷¨Ê½À´ÊµÏÖµÁ°æ½Ó¼û¡£¡£¡£¡£¡£¡£¡£ÔÚ´úºÅΪ¡°Tutto Chiaro¡±µÄ´ó¹æÄ£·´µÁ°æÐж¯ÖУ¬£¬ £¬ £¬£¬Òâ´óÀû½ðÈÚ¾¯Ô±¶ÓÁÐÔÚÈ«¹úÁìÓòÄÚÖ´ÐÐÁË100´ÎËѲ飬£¬ £¬ £¬£¬²é»ñÁË´óÁ¿ÓÐÖúÓÚ¼ø±ðÉæ°¸ÈËÔ±¼°È·¶¨·¸·¨ËùµÃµÄ¹Ø¼ü×ÊÁÏ¡£¡£¡£¡£¡£¡£¡£CINEMAGOALµÄÔË×÷»úÔ켫¾ß¼¼ÊõÏȽøÐÔ¡£¡£¡£¡£¡£¡£¡£¸ÃÀûÓÃÖ±½ÓÏνӵ½ºÏ·¨µÄÁ÷ýÌåÆ½Ì¨£¬£¬ £¬ £¬£¬Ê¹Óôӹú±í·þÎñÆ÷»ñÈ¡µÄÓÐЧ½âÃÜ´úÂë½øÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£ÏµÍ³ÀûÓÃλÓÚÒâ´óÀû¾³ÄÚµÄÐé¹¹»ú£¬£¬ £¬ £¬£¬Ã¿Èý·ÖÖӴӺϷ¨¶©ÔÄÖв¶»ñÓÐЧµÄÉí·ÝÑéÖ¤ºÍ½âÃÜ´úÂ룬£¬ £¬ £¬£¬¶øºó³Áзַ¢¸ø¿Í»§¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬ £¬ £¬£¬ÕâЩºÏ·¨¶©ÔľùʹÓÃÐéαÉí·ÝÐÅÏ¢ÔÚSky¡¢DAZN¡¢Netflix¡¢Disney+ºÍSpotifyµÈƽ̨ÉÏ¿ªÃ÷¡£¡£¡£¡£¡£¡£¡£Ó봫ͳµÄµÁ°æÁ÷ýÌå·ÖÆç£¬£¬ £¬ £¬£¬CINEMAGOAL²»½öÈÆ¹ýÁËÆ½Ì¨µÄ°²È«¹Ø±Õ£¬£¬ £¬ £¬£¬»¹ÌṩÁ˸üÓÅÖʵÄÅÔ¹ÛÂÄÀú£¬£¬ £¬ £¬£¬Óû§Ö±½Ó´ÓÔ­·þÎñÅÔ¹ÛÄÚÈݶø·Ç½Ó¹ÜÁÓÖʵÁ°æÁ÷£¬£¬ £¬ £¬£¬Í¬Ê±ÏµÍ³¸²¸ÇÁËÓû§µÄÕæÊµIPµØÖ·£¬£¬ £¬ £¬£¬´ó´ó½µµÍÁ˱»À¹½ØµÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£¡£¡£¾Ý¹À¼Æ£¬£¬ £¬ £¬£¬¸ÃµÁ°æÉú̬ÔÚÆäÔËÓªÆÚ¼äÔì³ÉµÄδ¸¶¶©ÔÄÊÕÈëËðʧԼΪ3ÒÚÅ·Ôª¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/legal/italy-disrupts-cinemagoal-piracy-app-that-stole-streaming-auth-codes/


4. ¼ÓÄÐ×ÓÔËÓª200Íǫ̀É豸½©Ê¬ÍøÂ磬£¬ £¬ £¬£¬ÔâÃÀ¼Ó½áºÏ¿ÛÁô


5ÔÂ22ÈÕ£¬£¬ £¬ £¬£¬ÃÀ¹úºÍ¼ÓÄô󵱾ֽüÈÕ¿ÛÁô²¢Ö¸¿ØÒ»Ãû23ËêµÄ¼ÓÄôóÄÐ×ÓÑŸ÷²¼¡¤°ÍÌØÀÕ£¨ÍøÃû¡°¶àÌØ¡±£©£¬£¬ £¬ £¬£¬×ïÃûÊÇÔËÓªÃûΪKimWolfµÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç¹æÄ£¾ªÈË£¬£¬ £¬ £¬£¬Ï°È¾ÁËÈ«Çò½ü200Íǫ̀É豸¡£¡£¡£¡£¡£¡£¡£°ÍÌØÀÕÓÚÖÜÈýÔÚä×Ì«»ª±»¼ÓÄÃ´óµ±¾ÖÆ¾¾ÝÒý¶ÉÁî¿ÛÁô£¬£¬ £¬ £¬£¬Ä¿Ç°ÕýÆÚ´ý±»Òý¶ÉÖÁÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£ËûÃæ¶ÔÒ»ÏîЭÖúºÍÖ§Ê¹ÍÆËã»úÈëÇÖµÄÖ¸¿Ø£¬£¬ £¬ £¬£¬×î¸ß¿ÉÅд¦10Äê½ûïÀ¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý°¢À­Ë¹¼ÓµØÓò°ä²¼µÄÐÌÊÂËß×´£¬£¬ £¬ £¬£¬·¨Âɲ¿ÃÅͨ¹ýIPµØÖ·¡¢ÔÚÏßÕË»§ÐÅÏ¢¡¢ÂòÂô¼Í¼ºÍÔÚÏßÐÂÎżÍ¼£¬£¬ £¬ £¬£¬³É¹¦½«°ÍÌØÀÕÓëKimWolf½©Ê¬ÍøÂçÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£¡£KimWolfÏÖʵÉÏÊÇÒ»¸öDDoS¹¥»÷³ö×â·þÎñƽ̨£¬£¬ £¬ £¬£¬±»ÍøÂç·¸×ï·Ö×ÓÓÃÀ´ÌáÒé¹æÄ £¿£¿£¿£¿£¿ £¿£¿ÕǰµÄ¹¥»÷£¬£¬ £¬ £¬£¬×î¸ß¹¥»÷Á÷Á¿¿¿½üÿÃë30Ì«±ÈÌØ£¬£¬ £¬ £¬£¬ÊÇÆäʱ¹«¿ªÅû¶µÄ×î´ó¹æÄ£DDoS¹¥»÷Ö®Ò»¡£¡£¡£¡£¡£¡£¡£°ÍÌØÀÕÑ¡È¡ÍøÂç·¸×ï¼´·þÎñģʽ£¬£¬ £¬ £¬£¬Ïò¿Í»§ÏúÊÛ¶ÔÖØ´óÊÜ¿ØÉè±¸ÍøÂçµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÕâЩ±»Ï°È¾µÄÉ豸ÖÖÀà·±¶à£¬£¬ £¬ £¬£¬Ô̺¬ÊýÂëÏà¿ò¡¢ÍøÂçÉãÏñÍ·¡¢»ùÓÚ°²×¿ÏµÍ³µÄµçÊӺкÍÁ÷ýÌåÉ豸µÈÎïÁªÍøÖÕ¶Ë¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç±»ÓÃÓÚ¶ÔÈ«ÇòÍÆËã»úºÍ·þÎñÆ÷ÌáÒ鳬¹ý25,000´Î¹¥»÷£¬£¬ £¬ £¬£¬¹¥»÷Ö¸±êÉõÖÁÔ̺¬ÃÀ¹ú¹ú·À²¿ÐÅÏ¢ÍøÂçµÄIPµØÖ·£¬£¬ £¬ £¬£¬¸ø²¿ÃÅÊܺ¦ÕßÔì³ÉÁ˳¬¹ý100ÍòÃÀÔªµÄ¾­¼ÃËðʧ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/us-and-canada-arrest-and-charge-suspected-kimwolf-botnet-admin/


5. Ç÷Ïò¿Æ¼¼½¨¸´ÒÑÔâÀûÓõÄApex OneÁãÈÕ·ì϶


5ÔÂ22ÈÕ£¬£¬ £¬ £¬£¬ÈÕ±¾ÍøÂ簲ȫÈí¼þ¹«Ë¾Ç÷Ïò¿Æ¼¼Òѽ¨¸´ÁËÒ»¸öÕë¶ÔÆäWindows°æApex OneÖն˰²È«Æ½Ì¨µÄÁãÈÕ·ì϶£¬£¬ £¬ £¬£¬¸Ã·ì϶Òѱ»·¢´Ë¿ÌÏÖʵ»·¾³ÖÐÔâµ½¹¥»÷ÀûÓᣡ£¡£¡£¡£¡£¡£Apex OneÊÇÇ÷Ïò¿Æ¼¼µÄÆóÒµ¼¶Öն˰²È«Æ½Ì¨£¬£¬ £¬ £¬£¬ÓÃÓÚ±£»£» £»£»£»£» £»¤ÆóÒµÍøÂçÃâÊܶñÒâÈí¼þ¡¢ÀÕË÷Èí¼þ¡¢ÎÞÎļþ¹¥»÷ºÍ»ùÓÚWebµÄÍþвµÈ¶àÖÖ°²È«Íþв¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±àºÅΪCVE-2026-34926£¬£¬ £¬ £¬£¬ÊÇÒ»¸ö´æÔÚÓÚApex One±¾µØ²¿Êð·þÎñÆ÷ÖеÄĿ¼±éÀú·ì϶£¬£¬ £¬ £¬£¬ÔÊÐíÓµÓÐÖÎÀíԱȨÏ޵ı¾µØ¹¥»÷Õß×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¾ÝÇ÷Ïò¿Æ¼¼ÖÜËÄÅû¶£¬£¬ £¬ £¬£¬¸ÃĿ¼±éÀú·ì϶¿ÉÄÜÔÊÐíÔ¤ÏȾ­¹ýÉí·ÝÑéÖ¤µÄ±¾µØ¹¥»÷ÕßÅú¸Ä·þÎñÆ÷ÉϵÄÃÜÔ¿±í£¬£¬ £¬ £¬£¬´Ó¶ø×¢Èë¶ñÒâ´úÂë²¢½«Æä²¿Êðµ½ÊÜÓ°Ïì×°ÖÃÖеĴúÀíÉÏ¡£¡£¡£¡£¡£¡£¡£±ØÒª×¢Ã÷µÄÊÇ£¬£¬ £¬ £¬£¬´Ë·ì϶½ö¿ÉÔÚApex OneµÄ±¾µØ²¿Êð°æ±¾ÉÏÀûÓ㬣¬ £¬ £¬£¬Ç±ÔÚ¹¥»÷Õß±ØÐëÕ¼ÓжÔApex One·þÎñÆ÷µÄ½Ó¼ûȨÏÞ£¬£¬ £¬ £¬£¬²¢ÇÒÒѾ­Í¨¹ýÆäËû·½Ê½»ñµÃÁË·þÎñÆ÷µÄÖÎÀíÍ´´¦¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü³É¹¦ÀûÓø÷ì϶µÄǰÌáÏ൱Ñϸñ£¬£¬ £¬ £¬£¬µ«Ç÷Ïò¿Æ¼¼ÖÒ¸æ³Æ£¬£¬ £¬ £¬£¬ÆäÍþвµý±¨ÏµÍ³¡°TrendAI¡±ÒѾ­¹Û²ìµ½ÖÁÉÙһ·ÔÚÏÖʵ»·¾³ÖÐÀûÓø÷ì϶µÄ³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£¼øÓڸ÷ì϶Òѱ»»îÔ¾ÀûÓ㬣¬ £¬ £¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©ÓÚ×òÈÕ½«CVE-2026-34926ÄÉÈëÆäÔÚ±»ÀûÓõķì϶ÁÐ±í£¬£¬ £¬ £¬£¬²¢ºÅÁîÁª¹ú»ú¹¹ÔÚ6ÔÂ4ÈÕ֮ǰʵÏÖÉ豸½¨²¹¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/


6. Drupal SQL×¢Èë·ì϶(CVE-2026-9082)Ôâ´ó¹æÄ£ÀûÓÃ


5ÔÂ24ÈÕ£¬£¬ £¬ £¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Microsoft Exchange ServerÖеÄÒ»¸ö·ì϶£¨±àºÅCVE-2026-9082£¬£¬ £¬ £¬£¬CVSSÆÀ·Ö9.8£©Ôö³¤µ½ÆäÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ÖÓ×£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÏÖʵÉÏÊÇDrupalÓÚ5ÔÂ20ÈÕ°ä²¼¸ß¶È¹Ø¼ü°²È«²¹¶¡ËùÕë¶ÔµÄSQL×¢Èë·ì϶£¬£¬ £¬ £¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÈëÇÖÔËÐÐPostgreSQLÊý¾Ý¿âµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£·ì϶ÀûÓÃÏÕЩÔÚ²¹¶¡°ä²¼ºóÁ¢¼´ÆðÍ·£¬£¬ £¬ £¬£¬48Ó×ʱÄÚ°²È«¹«Ë¾¾Í×·×Ùµ½ÁËÊýǧÆðÏÖʵ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÒ»¸öÖ¼ÔÚËãÕÊÊý¾Ý¿â²éÎʲ¢Ô¤·ÀSQL×¢ÈëµÄAPIÖÓ×£¡£¡£¡£¡£¡£¡£¸ÃAPIµÄȱµãÒâζ׏¥»÷ÕßÄܹ»·¢ËÍÌØÔìÒªÇ󣬣¬ £¬ £¬£¬ÏòʹÓÃPostgreSQLµÄÍøÕ¾×¢ÈëËÁÒâSQLºÅÁî¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝDrupal°ä²¼µÄ°²È«²¼¸æ£¬£¬ £¬ £¬£¬´Ë·ì϶ÔÊÐí¹¥»÷Õßµ¼ÖÂʹÓÃPostgreSQLÊý¾Ý¿âµÄÍøÕ¾Ôâ·êËÁÒâSQL×¢Èë¹¥»÷£¬£¬ £¬ £¬£¬¿ÉÄܵ¼ÖÂÐÅϢй¶£¬£¬ £¬ £¬£¬ÔÚijЩÇé¿öÏ»¹»áÒý·¢È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐлòÆäËû¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸üÁîÈËÓÇÓôµÄÊÇ£¬£¬ £¬ £¬£¬ÄäÃûÓû§Ò²Äܹ»ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£5ÔÂ22ÈÕ¸üÐµİ²È«²¼¸æÈ·ÈÏ£¬£¬ £¬ £¬£¬·çÏÕÆÀ·ÖÒѸüÐÂÒÔ·´Ó³Ä¿Ç°ÒÑÔÚÏÖʵ»·¾³Öмì²âµ½¹¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾ImpervaÔÚ·ì϶Åû¶ºóµÄÁ½ÌìÄÚ£¬£¬ £¬ £¬£¬¼à²âµ½Õë¶Ô65¸ö¹ú¶È½ü6000¸öDrupalÍøÕ¾µÄ³¬¹ý15000´Î¹¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£½üÒ»°ëµÄ¹¥»÷Ö¸±ê¼¯ÖÐÔÚÓÎÏ·ºÍ½ðÈÚ·þÎñ»ú¹¹£¬£¬ £¬ £¬£¬Õâ¿ÉÄÜÊÇÓÉÓÚÕâЩ»ú¹¹µÄƾ֤ºÍ²ÆÕþÊý¾Ý¼ÛÖµ½Ï¸ß¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.com/192566/uncategorized/u-s-cisa-adds-a-flaw-in-drupal-core-to-its-known-exploited-vulnerabilities-catalog.html