ÿÖÜÉý¼¶²¼¸æ-2023-01-10
°ä²¼¹¦·ò 2023-01-10
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Lucee_Admin_imgProcess.cfm_ËÁÒâÎļþдÈë[CVE-2021-21307] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÔÚÀûÓÃLuceeAdminÖеÄËÁÒâÎļþдÈë·ì϶¡£¡£¡£¡£¡£¡£¡£LuceeServerÊÇÒ»ÖÖ¶¯Ì¬µÄ¡¢»ùÓÚJava(JSR-223)µÄÏóÕ÷ºÍ¾ç±¾Ëµ»°£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ¼±¾çWebÀûÓ÷¨Ê½¿ª·¢¡£¡£¡£¡£¡£¡£¡£ÔÚ°æ±¾5.3.7.47¡¢5.3.6.68»ò5.3.5.96֮ǰµÄLuceeAdminÖдæÔÚδ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþдÈë·ì϶¡£¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20230110 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_WeiPHP_5.0_Îļþ¶ÁÈ¡[CNVD-2020-68596] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´ipÖ÷»ú£¬£¬£¬£¬£¬£¬£¬ÔÚÀûÓÃWeiphp5.0ǰ̨ÎļþËÁÒâ¶ÁÈ¡·ì϶½øÐй¥»÷£¬£¬£¬£¬£¬£¬£¬¶ÁÈ¡Êý¾Ý¿âÅäÖõÈÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20230110 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Struts2_S2-001/S2-002_´úÂëÖ´ÐÐ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | Struts2ÊÇÒ»¸ö»ùÓÚMVCÉè¼ÆÄ£Ê½µÄWebÀûÓÿò¼Ü£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ÓÉÓÚÓû§Ìá½»±íµ¥Êý¾Ý²¢ÇÒÑé֤ʧ°Üʱ£¬£¬£¬£¬£¬£¬£¬ºó¶Ë»á½«Óû§Ö®Ç°Ìá½»µÄ²ÎÊýֵʹÓÃOGNL±í°×ʽ%{value}½øÐнâÎö£¬£¬£¬£¬£¬£¬£¬¶øºó³ÁÐÂÌî³äµ½¶ÔÓ¦µÄ±íµ¥Êý¾ÝÖÓ×£¡£¡£¡£¡£¡£¡£ÀýÈç×¢²á»òµÇÂ¼Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬Ìύʧ°Üºó¶Ëͨ³£»áĬÈÏ·µ»ØÖ®Ç°Ìá½»µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚºó¶ËʹÓÃ%{value}¶ÔÌá½»µÄÊý¾ÝÖ´ÐÐÁËÒ»´ÎOGNL±í°×ʽ½âÎö£¬£¬£¬£¬£¬£¬£¬ËùÒÔÄܹ»Ö±½Ó»ú¹ØPayload½øÐкÅÁîÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20230110 |


¾©¹«Íø°²±¸11010802024551ºÅ