ÿÖÜÉý¼¶Í¨¸æ-2021-11-30

Ðû²¼Ê±¼ä 2021-12-10

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_QNAP-QTS_´úÂëÖ´ÐÐ[CVE-2017-6361][CNNVD-201702-940]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸´¢´æ¡¢¹ÜÀí¡¢±¸·Ý£¬¶àýÌåÓ¦Óü°Äþ¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚÄþ¾²Â©¶´¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´Ö´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_QNAP-QTS_ÃüÁîÖ´ÐÐ[CVE-2017-6360][CNNVD-201702-941]

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸´¢´æ¡¢¹ÜÀí¡¢±¸·Ý£¬¶àýÌåÓ¦Óü°Äþ¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚÄþ¾²Â©¶´¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´Ö´ÐÐÈÎÒâÃüÁ»ñÈ¡¹ÜÀíԱȨÏÞºÍÃô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_QNAP-QTS_ÃüÁîÖ´ÐÐ[CVE-2017-6359][CNNVD-201702-942]

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

QNAPQTSÊÇÖйúÍþÁªÍ¨£¨QNAPSystems£©¹«Ë¾µÄÒ»Ì×TurboNAS×÷ҵϵͳ¡£¸Ãϵͳ¿ÉÌṩµµ°¸´¢´æ¡¢¹ÜÀí¡¢±¸·Ý£¬¶àýÌåÓ¦Óü°Äþ¾²¼à¿ØµÈ¹¦Ð§¡£QNAPQTS4.2.4Build20170313֮ǰµÄ°æ±¾ÖдæÔÚÄþ¾²Â©¶´¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´»ñÈ¡¹ÜÀíԱȨÏÞ£¬Ö´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20211130

 


ʼþÃû³Æ£º

 TCP_Äþ¾²Â©¶´_Hadoop_Yarn_RPCδÊÚȨ·ÃÎÊ©¶´

Äþ¾²ÀàÐÍ£º

·ÇÊÚȨ·ÃÎÊ/ȨÏÞÈÆ¹ý

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃHadoopYarnµÄ©¶´½øÐÐδÊÚȨ·ÃÎÊ £»¶ÔÓÚ8032̻¶ÔÚ»¥ÁªÍøÇÒ먦ÆôkerberosµÄHadoopYarnResourceManager£¬±àдӦÓ÷¨Ê½µ÷ÓÃyarnClient.getApplications()¼´¿É¼ì²ìËùÓÐÓ¦ÓÃÐÅÏ¢ £»Hadoop×÷Ϊһ¸öÂþÑÜʽ¼ÆËãÓ¦Óÿò¼Ü£¬ÖÖÀ๦Ч·±¶à£¬¶øHadoopYarn×÷ΪÆäºËÐÄ×é¼þÖ®Ò»¡£

¸üÐÂʱ¼ä£º

20211130

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Apache_CouchDB_JSON_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-12636][CNNVD-201711-486]

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÕýÔÚÀûÓÃApacheCouchDBJSONÔ¶³ÌÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÉ豸¡£ApacheCouchDBÊÇÒ»¸ö¿ªÔ´Êý¾Ý¿â£¬×¨×¢ÓÚÒ×ÓÃÐԺͳÉΪ"Íêȫӵ±§webµÄÊý¾Ý¿â"¡£CouchDB»áĬÈÏ»áÔÚ5984¶Ë¿Ú¿ª·ÅRestfulµÄAPI½Ó¿Ú£¬ÓÃÓÚÊý¾Ý¿âµÄ¹ÜÀí¹¦Ð§¡£ËüÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢¸ñʽ£¬JavaScript×÷Ϊ²éѯÓïÑÔ£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£CouchDB½ÓÄÉ»ùÓÚErlangµÄJSON½âÎöÆ÷£¬Óë»ùÓÚJavaScriptµÄJSON½âÎöÆ÷²îÒ죬CouchDB¿ÉÒÔÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇɫ֨¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ·ÃÎÊ¿ØÖÆ£¬ÉõÖÁ°üÂÞÌåÏÖ¹ÜÀíÓû§µÄ_admin½ÇÉ«¡£¶ñÒâ¹¥»÷ÕßÀûÓÃÕâÒ»¹¦Ð§²¢½áºÏCVE-2017-12636©¶´£¬¿ÉÒÔʹ·Ç¹ÜÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý·ÃÎÊ·þÎñÆ÷ÉϵÄÈÎÒâshellÃüÁî¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Netgear_Nighthawk_R7000δÊÚȨԶ³Ì´úÂëÖ´ÐЩ¶´[CVE-2021-31802]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÕýÔÚÀûÓÃNetgea·ÓÉÆ÷Ô¶³ÌÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÉ豸¡£ÔÚNETGEARR7000ÉÏ´æÔÚÒ»¸öÉí·ÝÑéÖ¤ÅÔ·Äþ¾²Â©¶´¡£Â©¶´ÀûÓÃÀֳɺ󣬿ÉÒÔrootȨÏÞÖ´Ô¶³ÌÐдúÂë¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ʼþÃû³Æ£º

 HTTP_Äþ¾²Â©¶´_Primefaces_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-1000486][CNNVD-201801-112]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

PrimeFacesÊÇÒ»¸ö¿ªÔ´Óû§½çÃæ(UI)×é¼þ¿â£¬ÓÃÓÚ»ùÓÚJavaServerFacesµÄÓ¦Ó÷¨Ê½£¬ÓÉÍÁ¶úÆä¹«Ë¾PrimeTekInformatics´´½¨¡£Primefaces5.x´æÔÚÈõ¼ÓÃÜ©¶´£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20211130

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_D-Link_DWL-2600AP_²Ù×÷ϵͳÃüÁî×¢Èë©¶´[CVE-2019-20499/CVE-2019-20500/CVE-2019-20501][CNNVD-202003-201/CNNVD-202003-205/CNNVD-202003-204]

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

D-LinkDWL-2600APÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îÎÞÏß½ÓÈëµãÉ豸¡£D-LinkDWL-2600AP4.2.0.15RevA°æ±¾ÖдæÔÚ²Ù×÷ϵͳÃüÁî×¢Èë©¶´¡£¹¥»÷Õ߿ɽèÖúÉú´æÅäÖù¦Ð§ÀûÓøÃ©¶´Ö´ÐÐÈÎÒâµÄ²Ù×÷ϵͳÃüÁî¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Terramaster_TOS_ÃüÁî×¢Èë©¶´[CVE-2020-35665]

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×Ó¼¼Êõ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾´æÔÚ²Ù×÷ϵͳÃüÁî×¢Èë©¶´£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´Í¨¹ýÔÚʼþ²ÎÊýÖаüÂÞmakecvs.php×¢Èë²Ù×÷ϵͳÃüÁî¡£

¸üÐÂʱ¼ä£º

20211130

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_SQL_Server_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-0618][CNNVD-202002-496]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

SQLServerÊÇMicrosoft¿ª·¢µÄÒ»¸ö¹ØÏµÊý¾Ý¿â¹ÜÀíϵͳ(RDBMS)£¬ÊÇÏÖÔÚÊÀ½çÉϹ㷺ʹÓõÄÊý¾Ý¿âÖ®Ò»¡£¸Ã©¶´Ô´ÓÚ»ñµÃµÍȨÏ޵Ĺ¥»÷ÕßÏòÊÜÓ°Ïì°æ±¾µÄSQLServerµÄReportingServicesʵÀý·¢Ë;«ÐĽṹµÄÇëÇ󣬿ÉÀûÓôË©¶´ÔÚ±¨±í·þÎñÆ÷·þÎñÕÊ»§µÄÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211130

 

 

ʼþÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_ÆïÊ¿CMSÔ¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-35339][CNNVD-202102-1295]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÆïÊ¿CMSµÄ¡°ÍøÕ¾ÓòÃû¡±¶ÔÓ¦²ÎÊý½øÐдúÂëÖ´ÐвÙ×÷ £»ÆïÊ¿È˲ÅϵͳÊÇÒ»Ïî»ùÓÚPHPMYSQLΪºËÐÄ¿ª·¢µÄÒ»Ì×Ãâ·Ñ¿ªÔ´×¨ÒµÈ˲ÅÕÐÆ¸ÏµÍ³¡£Îª¸öÈËÇóÖ°ºÍÆóÒµÕÐÆ¸ÌṩÐÅÏ¢»¯½â¾ö·½°¸,ÆïÊ¿È˲Åϵͳ¾ß±¸Ö´ÐÐЧÂʸߡ¢Ä£°åÇл»×ÔÓÉ¡¢ºǫ́¹ÜÀí¹¦Ð§Áé»î¡¢Ä £¿é¹¦Ð§Ç¿´óµÈÌØµã¡£

¸üÐÂʱ¼ä£º

20211130

 


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_XStream_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-26217][CNNVD-202011-1441]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

Xstream½â×éʱ´¦ÖõÄÁ÷°üÂÞÀàÐÍÐÅÏ¢ÒÔÖØÐ´´½¨ÒÔǰ±àдµÄ¹¤¾ß¡£XStreamÒò´Ë»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐÂʵÀý¡£¹¥»÷Õß¿ÉÒÔÀûÓô¦ÖùýµÄÊäÈëÁ÷²¢Ìæ»»»ò×¢Èë¿ÉÒÔÖ´ÐÐÈÎÒâshellÃüÁîµÄ¹¤¾ß¡£

¸üÐÂʱ¼ä£º

20211130


ÐÞ¸Äʼþ



ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÃüÁî©¶´

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

÷ÈħӰϷ·¨Ê½(MaccmsPHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉÆµÄÇ¿´óÊÓÆµÓ°Ï·ÏµÍ³¡£ÍêÃÀÖ§³ÖÖÚ¶àÊÓÆµÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¸Ã©¶´Ö÷ÒªµÄ·¢ÉúÔ­ÒòÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£

¸üÐÂʱ¼ä£º

20211130