ÿÖÜÉý¼¶²¼¸æ-2022-10-18
°ä²¼¹¦·ò 2022-10-18ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_webuploader_0.1.15_ÎļþÉÏ´« |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃwebuploader0.1.15°æ±¾ÖдæÔÚµÄÎļþÉÏ´«·ì϶½øÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£¡£WebUploaderÊÇÓÉBaiduWebFE(FEX)ÍŶӿª·¢µÄÒ»¸öµ¥Ò»µÄÒÔHTML5ΪÖ÷£¬£¬£¬£¬£¬£¬FLASHΪ¸¨µÄÏÖ´úÎļþÉÏ´«×é¼þ¡£¡£¡£¡£¡£¡£ÔÚÏÖ´úµÄä¯ÀÀÆ÷ÀïÃæÄܳä·Ö²ûÑïHTML5µÄÓÅÊÆ£¬£¬£¬£¬£¬£¬Í¬Ê±ÓÖ²»ÞðÆúÖ÷Á÷IEä¯ÀÀÆ÷£¬£¬£¬£¬£¬£¬ÑØÓÃÔÀ´µÄFLASHÔËÐÐʱ£¬£¬£¬£¬£¬£¬¼æÈÝIE6+£¬£¬£¬£¬£¬£¬iOS6+,android4+¡£¡£¡£¡£¡£¡£Á½Ì×ÔËÐÐʱ£¬£¬£¬£¬£¬£¬Í¬ÑùµÄŲÓ÷½Ê½£¬£¬£¬£¬£¬£¬¿É¹©Óû§ËÁÒâÑ¡Óᣡ£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2963] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracleWebLogic10.3.6.0.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PHP-zerodiumºóÃÅ_ËÁÒâ´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄ·ÖÎö¹ý³ÌÖз¢ÏÖ£¬£¬£¬£¬£¬£¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»½Ù³ÖµÄÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬²¢ÇÒѡȡÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷£¬£¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢ÈËÔ±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£¡£¡£¡£¡£¡£Ä¿Ç°ÎªÖ¹PHP¹Ù·½²¢Î´¾Í¸ÃÊÂÎñ½øÐиü¶àÅû¶£¬£¬£¬£¬£¬£¬°µÊ¾Õâ´Î·þÎñÆ÷±»ºÚµÄ¾ßÌåϸ½ÚÈÔÔÚµ÷²é°ø±ß¡£¡£¡£¡£¡£¡£ÓÉÓÚ´ËÊÂÎñµÄÓ°Ï죬£¬£¬£¬£¬£¬PHPµÄ¹Ù·½´úÂë¿âÒѾ±»ÊØ»¤ÈËԱǨáãÖÁGitHubƽ̨£¬£¬£¬£¬£¬£¬Ö®ºóµÄÓйشúÂë¸üС¢Åú¸Ä½«»á¶¼ÔÚGitHubÉϽøÐС£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_WebLogic_·´ÐòÁл¯_XXE×¢Èë[CVE-2020-2949] |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃweblogic3.7.1.0,12.1.3.0.0,12.2.1.3.0,12.2.1.4.0°æ±¾´æÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬Í¨¹ýt3ºÍ̸´«µÝ¶ñÒâµÄÐòÁл¯Êý¾Ý´Ó¶ø´¥·¢XXE·ì϶£¬£¬£¬£¬£¬£¬¶Áȡָ±êϵͳÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14825] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃ10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0ºÍ14.1.1.0.0°æ±¾µÄweblogicÖдæÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳµÄȨÏÞ¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_×¢Èë¹¥»÷_apache_solr_XXE×¢Èë[CVE-2018-1308][CNNVD-201804-415] |
°²È«ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃApachesolr1.2-6.6.2ºÍ7.0.0-7.2.1°æ±¾ÖдæÔÚµÄXXE·ì϶½øÐÐÎļþ¶ÁÈ¡²Ù×÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳµÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£ApacheSolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷·þÎñ£¬£¬£¬£¬£¬£¬Ê¹ÓÃJava˵»°¿ª·¢£¬£¬£¬£¬£¬£¬ÖØÒª»ùÓÚHTTPºÍApacheLuceneʵÏֵġ£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-24616][CNNVD-202008-1195] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXMLJacksonµÄÔ¶³Ì´úÂëÖ´Ðзì϶ÏòÖ÷ÕÅip½øÐз´ÐòÁл¯¹¥»÷¡£¡£¡£¡£¡£¡£FasterXMLJacksonÊÇÃÀ¹úFasterXML¹«Ë¾µÄÒ»¿îºÏÓÃÓÚJavaµÄÊý¾Ý´¦Öù¤¾ß¡£¡£¡£¡£¡£¡£jackson-databindÊÇÆäÖеÄÒ»¸ö¾ßº±¼û¾Ý°ó¶¨Ö°ÄܵÄ×é¼þ¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Jackson_Databind_dbcp2_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-36180/CVE-2020-36182/CVE-2020-36184/CVE-2020-36185][CNNVD-202101-326/CNNVD-202101-325/CNNVD-202101-344/CNNVD-202101-337] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃFasterXMLjackson-databind<2.9.9.2ºÍ>=2.0.0,<=2.9.10.7°æ±¾ÖдæÔڵķ´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£¡£JacksonÊÇÒ»¸ö¿ÉÄܽ«java¶ÔÏóÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬£¬£¬£¬Ò²¿ÉÄܽ«JSON×Ö·û´®·´ÐòÁл¯Îªjava¶ÔÏóµÄ¿ò¼Ü |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_IBM_WebSphere_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-4279] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔIJÀûÓÃIBM_WebSphereV9.0.0.0-V9.0.0.11£¬£¬£¬£¬£¬£¬V8.5.0.0-V8.5.5.15£¬£¬£¬£¬£¬£¬v7.0ÖдæÔڵĴúÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳµÄȨÏÞ¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-2555] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃweblogic·´ÐòÁл¯·ì϶½øÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬£¬£¬OracleCoherenceΪOracleÈÚºÏÖÐÑë¼þÖеIJúÆ·£¬£¬£¬£¬£¬£¬ÔÚWebLogic12c¼°ÒÔÉϰ汾ÖÐĬÈϼ¯³Éµ½WebLogic×°ÖðüÖУ¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýt3ºÍ̸·¢ËÍ»ú¹ØµÄÐòÁл¯Êý¾Ý£¬£¬£¬£¬£¬£¬ÄܹýÔì³ÉºÅÁîÖ´ÐеijÉЧ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Atlassian_Confluence_Îļþ¶ÁÈ¡ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃAtlassianConfluence5.8.17֮ǰ°æ±¾ÖдæÔÚµÄÎļþ¶ÁÈ¡·ì϶½øÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬£¬£¬´Ó¶ø¶Áȡָ±êϵͳµÄÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£AtlassianonfluenceÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×רҵµÄÆóҵ֪ʶÖÎÀíÓëÐͬÈí¼þ£¬£¬£¬£¬£¬£¬Ò²Äܹ»ÓÃÓÚ¹¹½¨ÆóÒµWiKi¡£¡£¡£¡£¡£¡£¸ÃÈí¼þ¿ÉʵÏÖÍŶӳÉÔ±Ö®¼äµÄºÏ×÷ºÍ֪ʶ¹²Ïí¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Zyxel·À»ðǽ_ºÅÁîÖ´ÐÐ[CVE-2022-30525][CNNVD-202205-3104] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃZyxel·À»ðǽ5.00-5.21°æ±¾´æÔڵĺÅÁîÖ´Ðзì϶½øÐй¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£¡£ZyxelUSGFLEXÊÇÖйúZyxel¹«Ë¾µÄÒ»¿î·À»ðǽ£¬£¬£¬£¬£¬£¬Äܹ»Ìṩ½Ã½ÝµÄVPNÑ¡Ï£¬£¬£¬£¬£¬ÎªÔ¶³Ì¹¤×÷ºÍÖÎÀíÌṩ½Ã½ÝµÄ°²È«Ô¶³Ì½Ó¼û¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_JBoss_JMXInvokerServlet·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2015-7501] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃJBoss6.4.0֮ǰ°æ±¾ÖÐÔÚ/invoker/JMXInvokerServletµÄ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýApacheCommonsCollectionsÖеÄGadgetʵÏÖËÁÒâ´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£¡£¡£¡£¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬Äܹ»ÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬£¬£¬£¬£¬ÈçºóÃŵȡ£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Weblogic_Server_´úÂëÖ´ÐÐ[CVE-2021-2109][CNNVD-202101-1453] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃOracleWebLogic10.3.6.0.0¡¢12.1.3.0.0¡¢12.2.1.3.0¡¢12.2.1.4.0¡¢14.1.1.0.0°æ±¾´æÔڵĴúÂëÖ´Ðзì϶£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡£¡£¡£¡£¡£¡£WebLogicÊÇÃÀ¹úOracle¹«Ë¾³öÆ·µÄÒ»¸öapplicationserver£¬£¬£¬£¬£¬£¬È·ÇеÄ˵ÊÇÒ»¸ö»ùÓÚJAVAEE¼Ü¹¹µÄÖÐÑë¼þ£¬£¬£¬£¬£¬£¬WebLogicÊÇÓÃÓÚ¿ª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀí´óÐÍÉ¢²¼Ê½WebÀûÓá¢ÍøÂçÀûÓúÍÊý¾Ý¿âÀûÓõÄJavaÀûÓ÷þÎñÆ÷¡£¡£¡£¡£¡£¡£½«JavaµÄ¶¯Ì¬Ö°ÄܺÍJavaEnterprise³ß¶ÈµÄ°²È«ÐÔÒýÈë´óÐÍÍøÂçÀûÓõĿª·¢¡¢¼¯³É¡¢²¿ÊðºÍÖÎÀíÖ®ÖС£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20221018 |


¾©¹«Íø°²±¸11010802024551ºÅ