ÿÖÜÉý¼¶Í¨¸æ-2022-05-10

Ðû²¼Ê±¼ä 2022-05-10

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_GoAhead_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

GoAheadÊÇÒ»¸ö¿ªÔ´(ÉÌÒµÐí¿É)¡¢¼òµ¥¡¢ÇáÇÉ¡¢¹¦Ð§Ç¿´ó¡¢¿ÉÒÔÔÚ¶à¸öƽ̨ÔËÐеÄWebServer£¬¶àÓÃÓÚǶÈëʽϵͳ¡¢ÖÇÄÜÉ豸¡£ÆäÖ§³ÖÔËÐÐASP¡¢JavascriptºÍ³ß¶ÈµÄCGI·¨Ê½£¬Õâ¸ö©¶´¾Í·ºÆðÔÚÔËÐÐCGI·¨Ê½µÄʱºò¡£GoAheadÔÚ½ÓÊÕµ½ÇëÇóºó£¬½«»á´ÓURL²ÎÊýÖÐÈ¡³ö¼üºÍÖµ×¢²á½øCGI·¨Ê½µÄ»·¾³±äÁ¿£¬ÇÒÖ»¹ýÂËÁËREMOTE_HOSTºÍHTTP_AUTHORIZATION¡£ÎÒÃÇÄܹ»¿ØÖÆ»·¾³±äÁ¿£¬¾ÍÓкܶ๥»÷·½Ê½¡£ºÃ±ÈÔÚLinuxÖУ¬LD_¿ªÍ·µÄ»·¾³±äÁ¿ºÍ¶¯Ì¬Á´½Ó¿âÓйØ£¬ÈçLD_PRELOADÖÐÖ¸¶¨µÄ¶¯Ì¬Á´½Ó¿â£¬½«»á±»×Ô¶¯¼ÓÔØ£»LD_LIBRARY_PATHÖ¸¶¨µÄ·¾¶£¬·¨Ê½»áÈ¥ÆäÖÐѰÕÒ¶¯Ì¬Á´½Ó¿â¡£ÎÒÃÇ¿ÉÒÔÖ¸¶¨LD_PRELOAD=/proc/self/fd/0£¬ÒòΪ/proc/self/fd/0Êdz߶ÈÊäÈ룬¶øÔÚCGI·¨Ê½ÖУ¬POSTÊý¾ÝÁ÷¼´Îª³ß¶ÈÊäÈëÁ÷¡£ÎÒÃDZàÒëÒ»¸ö¶¯Ì¬Á´½Ó¿â£¬½«Æä·ÅÔÚPOSTBodyÖУ¬·¢Ë͸øhttp://target/cgi-bin/index?LD_PRELOAD=/proc/self/fd/0£¬CGI¾Í»á¼ÓÔØÎÒÃÇ·¢Ë͵Ķ¯Ì¬Á´½Ó¿â£¬Ôì³ÉÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_FreePBX_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

FreePBXÊÇÒ»¸ö×îÇ¿´óµÄGUI£¨»ùÓÚÍøÒ³µÄ£©ÅäÖÃAsteriskµÄ¹¤¾ß£¬ÔÚÆä13ºÍ14°æ±¾´æÔÚÄþ¾²Â©¶´£¬Ö÷»úÓб»Ö´ÐÐÈÎÒâϵͳÃüÁîµÄ·çÏÕ¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_WordPress_Levo_Slideshow_2.3_ÈÎÒâÎļþÉÏ´«Â©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

WordPressLevo-Slideshow²å¼þ2.3°æ±¾´æÔÚÎļþÉÏ´«Â©¶´£¬¸Ã©¶´Ô´ÓÚ¶ÔÉÏ´«Îļþºó׺¼ì²â²»ÑϽ÷£¬¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ¿ØÖÆÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_CA_Privileged_Access_Manager_ÃüÁî×¢Èë©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

CAPrivilegedAccessManager2.8.2¼°¸üÔç°æ±¾ÖдæÔÚÒ»¸öÃüÁî×¢Èë©¶´£¬¸Ã©¶´ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÖÆÇëÇóÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PixelStor_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2020-6756][CNNVD-202001-346]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

RasilientPixelStor5000K:4.0.1580-20150629£¨KDI°æ±¾£©ÖеÄlanguageOptions.phpÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýlang²ÎÊýÔ¶³ÌÖ´ÐÐÃüÁî¡£

¸üÐÂʱ¼ä£º

20220510

 

½ØÍ¼20220510161912.png

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PmWiki_PageListSort_Ô¶³Ì´úÂë×¢Èë©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

PmWikiÊÇÒ»ÖÖ»ùÓÚWiki¼¼ÊõµÄ¿ªÔ´¶àÈËЭ×÷Õ¾µã´´½¨ºÍά»¤¹¤¾ß¡£PmWiki2.0.0µ½2.2.34°æ±¾ÖдæÔÚÔ¶³ÌPHP´úÂë×¢Èë©¶´¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÔÚÊÜÓ°ÏìµÄÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖÐ×¢ÈëºÍÖ´ÐÐÈÎÒâPHP´úÂ룬Õâ¿ÉÄÜ»á´Ù½ø¹¥»÷Õß²Ù¿ØÓ¦Ó÷¨Ê½ºÍµ×²ãϵͳ£¬»òÕßÔì³ÉÆäËûµÄ¹¥»÷¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Basilic1.5.14-diff.php_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

BasilicÖдæÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´ÔÚÊÜÓ°ÏìÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâÃüÁî¡£Basilic1.5.14°æ±¾ÖдæÔÚ©¶´£¬ÆäËû°æ±¾Ò²¿ÉÄÜÊܵ½Ó°Ïì¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_WAN-Emulator-v2.3_ÈÎÒâÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

WANEmulatorÊǹãÓòÍøÂçÄ£ÄâÆ÷¡£WANEmulator´æÔÚ·Ç·¨·ÃÎÊ©¶´£¬dosu¶þ½øÖÆÎļþ°²×°ÁËsetuidrootºó¿É´¥·¢´Ë©¶´£¬µ¼Öµ±µØ¹¥»÷Õß»ñÈ¡rootȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ºÃÊÓͨÊÓÆµ»áÒéϵͳ_ÈÎÒâÎļþÏÂÔØ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ºÃÊÓͨÊÓÆµ»áÒéÆóÒµ°æ·þÎñÆ÷¹ÜÀíºǫ́´æÔÚÈÎÒâÎļþÏÂÔØÂ©¶´£¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´»ñÈ¡Ãô¸ÐÐÅÏ¢¡£Ä¿Ç°£¬¹©Ó¦ÉÌÐû²¼ÁËÄþ¾²Í¨¸æ¼°Ïà¹Ø²¹¶¡ÐÅÏ¢£¬ÐÞ¸´ÁË´Ë©¶´¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Ruckus_IoT_Controller_Éí·ÝÑéÖ¤ÈÆ¹ý©¶´[CVE-2020-26879][CNNVD-202010-1425]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

RuckusIoTController£¨<=1.5.1.0.21°æ±¾£©ÖдæÔÚÒ»¸öÉí·ÝÑéÖ¤ÈÆ¹ý©¶´¡£¸Ã©¶´ÊÇÓÉÓÚ¶Ô¾«ÐÄÉè¼ÆµÄHTTPÇëÇó´¦Öò»Í×Ôì³ÉµÄ£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿±ê·þÎñÆ÷·¢Ë;«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´ÀûÓøÃ©¶´£¬ÀÖ³ÉÀûÓÿÉÄÜÔÊÐí¹¥»÷ÕßÈÆ¹ýÉí·ÝÑéÖ¤¡£

¸üÐÂʱ¼ä£º

20220510

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Vtiger-CRM-°²×°½Å±¾_δÊÚÈ¨ÖØ×°

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

VtigerCRMÊÇÃÀ¹úVtiger¹«Ë¾µÄÒ»Ì×»ùÓÚSugarCRM¿ª·¢µÄ¿Í»§¹ØÏµ¹ÜÀíϵͳ£¨CRM£©£¬ËüÌṩ¹ÜÀí¡¢ÊÕ¼¯¡¢·ÖÎö¿Í»§ÐÅÏ¢µÈ¹¦Ð§¡£InstallModuleÊÇÆäÖеÄÒ»¸ö°²×°Ä£¿é¡£VtigerCRM6.0°æ±¾µÄInstallÄ£¿éÖеÄviews/Index.php½Å±¾ÖдæÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÏÞÖÆ·ÃÎÊȨÏÞ¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͰüÂÞX-Requested-WithHTTPÍ·ÉèÖõÄÇëÇóÀûÓøÃ©¶´ÖØ×°Ó¦Ó÷¨Ê½¡£

¸üÐÂʱ¼ä£º

20220510


ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_systeminfo_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÃüÁîµÄ»ØÏÔÐÅÏ¢£¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ£¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÃüÁîµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220510