ÿÖÜÉý¼¶²¼¸æ-2021-11-02

°ä²¼¹¦·ò 2021-11-09

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_UEditor±à×ëÆ÷_ËÁÒâÎļþÉÏ´«·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃUEditor±à×ëÆ÷µÄcontroller.ashxÒ³ÃæÉÏ´«Îļþ¡£¡£¡£¡£¡£¡£UEditorÊÇÓɰٶÈWEBǰ¶ËÑз¢²¿¿ª·¢µÄËù¼û¼´ËùµÃµÄ¿ªÔ´¸»Îı¾±à×ëÆ÷£¬£¬£¬ £¬ £¬£¬£¬£¬¸ÃÒ³Ãæ´æÔÚÒ»¸öÉÏ´«ËÁÒâÎļþµÄ·ì϶£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷Õßͨ¹ýαÔìǰ׺ºÏ·¨µÄÎļþÃû£¬£¬£¬ £¬ £¬£¬£¬£¬ÖÐÑëÔö³¤½Ø¶Ï·ûºÅ£¬£¬£¬ £¬ £¬£¬£¬£¬Ê¹µÃËÁÒâÎļþ¾ù¿ÉÉÏ´«¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102


 

ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-24616][CNNVD-202008-1195]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´Ðзì϶ÏòÖ÷ÕÅip½øÐз´ÐòÁл¯¹¥»÷£»£»£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄ×é¼þ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102


 

ÊÂÎñÃû³Æ£º

TCP_ľÂí_NetWire±äÖÖ_Ô¶¿ØÄ¾Âí

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWin32.NetWire¡£¡£¡£¡£¡£¡£Win32.NetWireÊÇÒ»¸öÖ°ÄÜ׳´óµÄÔ¶¿ØÄ¾Âí£¬£¬£¬ £¬ £¬£¬£¬£¬¿ÉÔ¶³Ì½ÚÔìÊܺ¦Ö÷»úÖ´ÐÐËÁÒâ²Ù×÷¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃÊÂÎñ_·¢ÏÖʹÓÃunicode±àÂë

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

JavaĬÈϵıàÂ뷽ʽΪUnicode£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚjava˵»°ºÍ²¿ÃÅ.net·¨Ê½ÖУ¬£¬£¬ £¬ £¬£¬£¬£¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_URLȨÏÞÈÆ¹ý·ì϶[CVE-2020-1957][CNNVD-202003-1579]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ApacheShiroÊÇÒ»¸ö׳´óÇÒÒ×ÓõÄJava°²È«¿ò¼Ü£¬£¬£¬ £¬ £¬£¬£¬£¬ËüÄܹ»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£¡£¡£Ä¿Ç°³£¼û¼¯³ÉÓÚ¸÷ÀàÀûÓÃÖнøÐÐÉí·ÝÑéÖ¤£¬£¬£¬ £¬ £¬£¬£¬£¬ÊÚȨµÈ¡£¡£¡£¡£¡£¡£¶ÔÓÚApacheShiro1.5.1֮ǰµÄ°æ±¾£¬£¬£¬ £¬ £¬£¬£¬£¬µ±½«ApacheShiroÓëSpring½ÚÔìÆ÷һ·ʹÓÃʱ£¬£¬£¬ £¬ £¬£¬£¬£¬¹¥»÷ÕßÌØÔìÒªÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXML_JacksonµÄÔ¶³Ì´úÂëÖ´Ðзì϶ÏòÖ÷ÕÅip½øÐз´ÐòÁл¯¹¥»÷£»£»£»£»£»FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄ×é¼þ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_VantageVelocity_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2020-9020][CNNVD-202002-889]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

IterisVantageVelocityFieldUnitÊÇÃÀ¹úIteris¹«Ë¾µÄÒ»¿î··¼à²âÏÖ³¡É豸¡£¡£¡£¡£¡£¡£IterisVantageVelocityFieldUnit2.3.1°æ±¾¡¢2.4.2°æ±¾ºÍ3.0°æ±¾ÖдæÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£ÔÚVantageVelocity²úÆ·SynchronizeWithNTPServer´¦£¬£¬£¬ £¬ £¬£¬£¬£¬Óû§Äܹ»ÉèÖÃÖ¸¶¨µÄntp·þÎñÆ÷µØÖ·¡£¡£¡£¡£¡£¡£ÓÉÓÚδ¶ÔÓû§Ð´ÈëµÄhtmlNtpServer±äÁ¿¹ýÂË£¬£¬£¬ £¬ £¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâÄÚÈÝ´¥·¢ºÅÁîÖ´Ðзì϶¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Terramaster-TOS-exportUser.php_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-15568][CNNVD-202101-2598]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

TerramasterTOSÊÇÖйúÌúÍþÂí£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬£¬£¬ £¬ £¬£¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£TerraMasterTOSbefore4.1.29´æÔÚÊäÈëÑéÖ¤ÃýÎó·ì϶£¬£¬£¬ £¬ £¬£¬£¬£¬¸Ã·ì϶ԴÓÚÎÞЧµÄ²ÎÊý²é³­£¬£¬£¬ £¬ £¬£¬£¬£¬µ¼Ö´úÂëÒÔroot×¢Èë¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Master-IP-CAM-01_ºÅÁî×¢Èë·ì϶[CVE-2020-10971][CNNVD-202005-271][CVE-2019-8387][CNNVD-201902-725][CVE-2019-8387][CNNVD-201902-725]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

MasterIPCAM01ÊÇÒ»¿îÍøÂçÉãÏñ»ú¡£¡£¡£¡£¡£¡£MasterIPCAM013.3.4.2103°æ±¾ÖдæÔÚºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¸Ã·ì϶ԴÓÚ±í²¿ÊäÈëÊý¾Ý»ú¹Ø¿ÉÖ´ÐкÅÁî¹ý³ÌÖУ¬£¬£¬ £¬ £¬£¬£¬£¬ÍøÂçϵͳ»ò²úƷδÕýÈ·¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨ºÅÁî¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_InoERP_0.7.2_Ô¶³Ì´úÂëÖ´ÐÐ/ÊäÈëÑéÖ¤ÃýÎó·ì϶[CVE-2020-28870]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

InoERPÊÇÒ»Ì×»ùÓÚPHPµÄ¿ªÔ´ÆóÒµÖÎÀíϵͳ¡£¡£¡£¡£¡£¡£InoERPÖдæÔÚÊäÈëÑéÖ¤ÃýÎó/Ô¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬ £¬ £¬£¬£¬£¬¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδ¶ÔÊäÈëµÄÊý¾Ý½øÐÐÕýÈ·µÄÑéÖ¤£¬£¬£¬ £¬ £¬£¬£¬£¬¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«É¨Ãè_WEBɨÃèÆ÷ÐÐΪ

°²È«ÀàÐÍ£º

°²È«É¨Ãè

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPµØÖ·µÄÖ÷»úÔÚʹÓÃWEBɨÃ蹤¾ß¶ÔÖ÷ÕÅIPµØÖ·½øÐзì϶ɨÃè¡£¡£¡£¡£¡£¡£WEBɨÃèÆ÷ͨ³£Êǹ¥»÷ÕßÓÃÀ´×ö·þÎñɨÃè¡¢·ì϶²âÊԵȡ£¡£¡£¡£¡£¡£Í¨¹ý·ì϶ɨÃ裬£¬£¬ £¬ £¬£¬£¬£¬Äܹ»×Ô¶¯¼±¾ç̽²âһЩ³£¼û·ì϶Çé¿ö£¬£¬£¬ £¬ £¬£¬£¬£¬µ±´æÔÚ·ì϶ʱ±ãÓÚºóÐø½øÐÐÀûÓù¥»÷¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.DTLoaderÏÂÔØÕßľÂí_ÏÂÔØ¶ñÒâPayload

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½DTLoaderÏÂÔØÕßľÂí±ÉÈËÔØ¶ñÒâPayload¡£¡£¡£¡£¡£¡£DTLoaderÊÇÒ»¸öÏÂÔØÕßľÂí£¬£¬£¬ £¬ £¬£¬£¬£¬ÕƹÜÏÂÔØ¶ñÒâ´úÂ룬£¬£¬ £¬ £¬£¬£¬£¬ÏÂÔØµÄ¶ñÒâ´úÂëÓÐAgentTesla,NanoCoreµÈ¡£¡£¡£¡£¡£¡£Ê¹ÓÃDTLoaderC#˵»°±àд¶ø³É£¬£¬£¬ £¬ £¬£¬£¬£¬Í¨³£¾­¹ý»ìºÏ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃÊÂÎñ_·¢ÏÖÂÅ´Îunicode±àÂëÐÐΪ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

JavaĬÈϵıàÂ뷽ʽΪUnicode£¬£¬£¬ £¬ £¬£¬£¬£¬ÔÚjava˵»°ºÍ²¿ÃÅ.net·¨Ê½ÖУ¬£¬£¬ £¬ £¬£¬£¬£¬unicode±àÂë¿É±»×Ô¶¯´¦ÖýâÎö³É×Ö·û´®¡£¡£¡£¡£¡£¡£ÂÅ´Îunicode±àÂë¿ÉÄÜΪ¹¥»÷Õß³¢ÊÔÈÆ¹ý¼ì²âÉ豸µÄÐÐΪ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Fastjson·ì϶_hex±àÂëÀûÓÃ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬£¬£¬ £¬ £¬£¬£¬£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬£¬£¬ £¬ £¬£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬ £¬ £¬£¬£¬£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬ £¬ £¬£¬£¬£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬£¬£¬ £¬ £¬£¬£¬£¬ÀûÓÃÁìÓòºÜ¹ã¡£¡£¡£¡£¡£¡£¹¥»÷³É¹¦£¬£¬£¬ £¬ £¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£fastjson¿É½ÓÊܲ¢½âÎöhex±àÂëÄÚÈÝ£¬£¬£¬ £¬ £¬£¬£¬£¬Òò¶ø¹¥»÷Õß¿ÉÀûÓÃhex±àÂëÈÆ¹ý¼ì²âÉ豸¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_GitLab_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2021-22205][CNNVD-202104-1685]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

GitLabÊÇÓÉGitLabInc.¿ª·¢£¬£¬£¬ £¬ £¬£¬£¬£¬Ê¹ÓÃMITÐí¿ÉÖ¤µÄ»ùÓÚÍøÂçµÄGit²Ö¿âÖÎÀí¹¤¾ß£¬£¬£¬ £¬ £¬£¬£¬£¬ÓµÓÐissue¸ú×ÙÖ°ÄÜ¡£¡£¡£¡£¡£¡£ËüÊÇʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÔÚ´Ë»ù´¡ÉϴÆðÀ´µÄweb·þÎñ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚGitLabûÓÐÕýÈ·µÄ´¦Öô«ÈëµÄͼÏñÎļþ£¬£¬£¬ £¬ £¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓø÷ì϶»ú¹Ø¶ñÒâÊý¾ÝÖ´ÐÐÔ¶³ÌºÅÁ£¬£¬ £¬ £¬£¬£¬£¬×îÖÕÔì³É·þÎñÆ÷Ãô¸ÐÐÔÐÅϢй¶¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102


 

ÊÂÎñÃû³Æ£º

 HTTP_°²È«·ì϶_GitLab_Ô¶³ÌºÅÁîÖ´Ðзì϶

[CVE-2021-22205][CNNVD-202104-1685]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

GitLabÊÇÓÉGitLabInc.¿ª·¢£¬£¬£¬ £¬ £¬£¬£¬£¬Ê¹ÓÃMITÐí¿ÉÖ¤µÄ»ùÓÚÍøÂçµÄGit²Ö¿âÖÎÀí¹¤¾ß£¬£¬£¬ £¬ £¬£¬£¬£¬ÓµÓÐissue¸ú×ÙÖ°ÄÜ¡£¡£¡£¡£¡£¡£ËüÊÇʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬£¬ £¬ £¬£¬£¬£¬²¢ÔÚ´Ë»ù´¡ÉϴÆðÀ´µÄweb·þÎñ¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÓÉÓÚGitLabûÓÐÕýÈ·µÄ´¦Öô«ÈëµÄͼÏñÎļþ£¬£¬£¬ £¬ £¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÀûÓø÷ì϶»ú¹Ø¶ñÒâÊý¾ÝÖ´ÐÐÔ¶³ÌºÅÁ£¬£¬ £¬ £¬£¬£¬£¬×îÖÕÔì³É·þÎñÆ÷Ãô¸ÐÐÔÐÅϢй¶¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102



ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃû½âÎöÒªÇó2

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö£º

¼ì²âµ½ÍÚ¿óľÂíÊÔͼÏνÓÓòÃû·þÎñÆ÷½âÎö¿ó³ØµØÖ·¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£ÍÚ¿óľÂí³¢ÊÔÏÎ½Ó¿ó³Ø£¬£¬£¬ £¬ £¬£¬£¬£¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý£¬£¬£¬ £¬ £¬£¬£¬£¬¿÷ËðCPU×ÊÔ´¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_fastjson_1.2.47_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

FastjsonÊÇÒ»¸öJava¿â£¬£¬£¬ £¬ £¬£¬£¬£¬Äܹ»½«Java¶ÔÏóת»»ÎªJSONÌåʽ£¬£¬£¬ £¬ £¬£¬£¬£¬fastjsonÔÚ1.2.47ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ°²È«·ì϶¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐÄ»ú¹ØµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬ £¬ £¬£¬£¬£¬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬ £¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20211102