一、蓝凌EKP存在sys_ui_component远程命令执行漏洞
二、亿赛通数据泄露防护(DLP)系统NoticeAjax接口存在SQL注入漏洞
三、天问物业ERP系统AreaAvatarDownLoad存在任意文件读取漏洞
四、赛蓝企业管理系统ReadTxtLog存在任意文件读取漏洞
五、赛蓝企业管理系统GetJSFile存在任意文件读取漏洞
六、数字通指尖云平台-智慧政务payslip SQL注入漏洞
七、通天星CMSV6车载定位监控平台disable存在SQL注入
八、北京致远互联软件股份有限公司AnalyticsCloud分析云存在任意文件读取漏洞
九、网传天擎0day rce
十、网传某康综合安防0day
十一、SuiteCRM系统接口responseEntryPoint存在SQL注入漏洞(CVE-2024-36412)
十二、亿赛通数据泄露防护(DLP)系统NetSecConfigAjax接口存在SQL注入漏洞
十三、用友NC querygoodsgridbycode存在SQL注入漏洞
十四、云课网校系统uploadImage存在任意文件上传漏洞
十五、NC系统blobRefClassSearch接口中pk_org参数的sql注入漏洞
十六、浪潮云财务系统存在命令执行
十七、通天星主动安全监控云平台远程代码执行漏
十八、H3C Workspace 云桌面 远程命令执行漏洞(XVE-2024-8180
十九、润乾报表前台任意文件上传漏洞
二十、启明星辰 天玥网络安全审计系统 SQL 注入漏洞
二十一、致远 OA fileUpload.do 前台文件上传绕过漏洞
二十二、(指挥调度平台invite_one_member存在远程命令执行漏洞
二十三、指挥调度平台ajax_users存在SQL注入漏洞
二十四、锐捷 RG-NBS2026G-P交换机WEB 管理ping.htm未授权访问漏洞
二十五、万户协同办公平台ezoffice DocumentEdit_unite.jsp SQL注入漏洞
二十六、用友U8 Cloud MonitorServlet 存在反序列化漏洞
二十八、U8cloud系统MeasureQueryframeAction SQL注入漏洞
二十九、用友 GRP-A-Cloud 政府财务云 selectGlaDatasourcePreview SQL注入漏洞
三十、蓝凌KEP前台RCE漏洞
三十一、泛微E-office-10接口leave_record.php存在SQL注入漏洞
三十二、1Panel面板最新前台RCE漏洞(CVE-2024-39911)
三十三、Netgear-WN604接口downloadFile.php信息泄露漏洞(CVE-2024-6646)
三十四、Nacos远程代码执行漏洞
三十五、LiveNVR流媒体服务软件接口存在未授权访问漏洞 livenvr 青柿视频管理系统 channeltree 存在未授权访问漏洞
三十六、fogproject系统接口export.php存在远程命令执行漏洞(CVE-2024-39914)
三十七、全息AI网络运维平台ajax_cloud_router_config.php存在命令执行漏洞
三十八、广联达OA接口ArchiveWebService存在XML实体注入漏洞
三十九、用友CRM系统import.php任意文件上传漏洞
四十、用友GRP A++Cloud政府财务云存在任意文件读取漏洞
四十一、瑞友天翼应用虚拟化系统hmrao.php存在SQL注入漏洞
四十二、红海云eHR-PtFjk.mob存在任意文件上传漏洞
四十三、福建科立讯通信指挥调度管理平台ajax_users.php存在SQL注入漏洞、
四十四、泛微OA E-Cology ln.FileDownload文件读取漏洞
四十五、大华DSS数字监控系统存在SQL注入漏洞
124.222.56.103
2409:8a34:423:7910:5538:8be:26e9:f4a7
49.232.195.9
218.60.117.33
218.60.117.242
140.246.68.149
45.136.18.39
39.105.173.98
103.218.92.234
34.170.36.96
45.128.232.128
23.95.190.190
222.85.139.162
119.45.164.105
39.105.53.172
129.211.180.50
146.56.201.123
104.152.52.34
123.249.91.159
3.15.154.27
180.143.102.239
4.151.229.42
103.39.93.93
8.219.150.33
146.190.152.115
217.60.247.66
122.117.51.33
223.76.215.193
165.154.4.145
178.239.146.228
165.154.23.25
123.207.51.103
45.128.232.22
103.82.195.126
52.228.153.192
60.210.21.250
118.107.44.111
39.172.74.243
18.222.137.194
103.146.22.100
159.138.3.90
213.169.137.235
178.238.224.39
27.222.11.186
45.90.46.145
95.111.233.231
4.255.99.211
68.183.225.172
221.10.124.142
128.199.203.116
165.154.21.188
185.4.28.64
212.113.102.66
165.154.21.143
103.232.122.33
103.119.17.99
185.229.119.127
43.143.240.248
113.125.14.174
223.113.128.228
223.113.128.141
118.194.255.11
164.92.161.119
152.32.183.31
159.89.194.184
91.92.251.38
149.50.130.85
49.0.203.169
183.15.122.44
203.34.56.254
213.199.57.254
152.32.171.126
188.130.207.41
39.109.126.254
62.108.52.76
212.113.102.134
124.156.204.44
156.236.72.27
47.245.34.195
8.209.223.148
103.173.227.187
152.32.247.54
119.45.29.30
157.66.49.10
162.215.23.125
34.67.180.178
27.124.53.40
34.134.31.82
156.237.192.18
23.94.245.126
42.193.125.168
23.94.245.124
23.94.245.125
23.94.245.122
23.94.245.123
23.94.245.120
23.94.245.121
18.158.145.15
223.255.246.169
162.215.23.134
162.215.23.135
23.94.234.94
34.81.227.53
162.215.23.132
23.94.234.92
23.94.234.93
162.215.23.131
38.6.193.10
222.186.11.172
159.75.111.243
23.94.245.119
27.124.7.107
39.98.196.145
185.174.101.80
23.94.245.117
23.94.245.118
23.94.245.115
23.94.245.116
37.37.183.28
23.94.245.114
35.224.58.250
38.6.176.188
39.105.107.96
159.75.164.33
23.247.128.40
3.11.124.241
4.180.40.83
18.223.161.236
157.230.9.141
3.228.106.146
39.34.79.130
182.92.157.25
185.104.181.135
159.65.130.146
162.215.23.146
31.42.185.190
162.215.23.144
39.106.5.215
162.215.23.140
185.117.118.21
39.105.197.88
38.181.78.247
162.215.23.147
162.215.23.148
156.238.233.183
156.238.225.81
35.221.150.166
156.247.33.205
159.203.166.179
23.224.61.53
159.100.248.100
3.78.29.203
221.190.222.201
157.20.182.5
185.125.50.39
3.236.126.155
156.237.192.19
162.14.73.154
25.31.95.31
159.89.187.246
162.215.23.168
159.75.104.8
162.215.23.165
162.215.23.166
39.64.239.162
159.223.224.93
162.215.23.164
38.6.175.122
36.138.173.47
162.215.23.208
27.124.53.83
23.94.230.184
24.199.120.22
23.94.230.189
35.84.184.254
23.95.248.203
39.101.71.208
23.95.248.204
23.95.248.205
23.95.248.206
39.105.130.94
23.95.248.200
23.95.248.201
23.95.248.197
23.95.248.198
39.100.89.193
4.233.217.192
34.45.75.65
38.46.14.58
38.46.14.59
36.134.129.16
38.6.185.10
198.44.250.238
23.224.144.212
38.54.57.79
38.46.14.60
34.198.241.131
159.75.164.94
3.136.65.236
3.106.28.151
23.95.181.154
182.92.4.102
23.95.181.153
180.101.25.48
159.75.104.197
23.95.181.152
3.66.145.34
221.15.241.171
23.95.181.151
23.95.181.150
185.11.61.124
158.220.115.82
42.192.36.31
38.60.252.118
23.95.181.158
23.94.233.124
23.95.181.157
37.24.111.27
23.95.181.156
23.95.181.155
185.150.26.240
18.170.246.72
27.54.170.50
185.17.165.28
16.163.148.219
222.188.218.2
162.215.23.171
38.147.172.17
4.246.230.34
184.72.112.171
162.215.23.176
38.55.197.174
37.187.27.240
34.28.72.212
185.174.101.126
41.215.243.24
38.47.107.44
38.12.42.216
156.245.25.173
39.98.119.229
31.220.30.244
162.215.23.182
39.107.117.48
162.215.23.188
39.104.208.240
4.180.6.242
31.230.52.175
3.216.133.137
156.238.234.187
34.142.201.103
157.90.254.254
38.6.221.41
162.215.23.192
156.245.19.127
3.127.253.86
39.105.141.35
162.215.23.191
3.8.115.155
39.100.79.87
162.215.23.198
162.215.23.196
35.171.228.255
157.230.31.26
39.100.91.89
23.27.127.199
34.16.198.174
31.172.87.230
222.112.248.181
39.105.114.179
23.95.213.61
34.237.94.238
157.230.254.3
34.84.42.35
159.100.248.255
183.144.22.56
31.192.236.82
23.94.234.85
41.216.183.135
3.6.115.64
31.124.151.205
23.94.234.89
162.215.23.128
23.94.234.87
31.128.32.22
182.92.214.111
23.95.248.202
3.18.245.102
18.221.155.0
34.206.138.66
181.214.152.130
35.166.57.84
157.66.25.16
39.105.24.228
183.254.32.172
3.0.250.71
185.158.248.107
159.89.204.198
38.55.251.221
23.95.235.10
38.6.193.9
162.215.23.220
185.64.246.150
27.50.63.135
38.6.193.7
23.94.123.235
162.215.23.109
27.25.138.254
42.192.84.184
185.154.52.150
184.147.209.221
162.215.23.108
35.238.182.197
39.96.162.136
162.215.23.225
18.140.63.42
34.95.215.178
42.194.133.168
162.215.23.111
37.19.201.131
219.157.135.10
222.239.35.173
162.215.23.117
185.170.144.142
159.100.248.25
40.115.32.175
159.100.246.87
42.51.37.127
162.215.23.123
23.239.19.42
162.215.23.120
29.54.63.192
35.197.55.147
42.193.248.127
18.253.127.167
34.195.136.4
18.189.106.45
39.96.116.31
35.204.170.221
185.172.128.6
39.100.182.56
18.217.214.178
182.92.179.238
27.50.63.215
38.147.186.101
24.144.86.72
34.105.74.82
25.62.225.224
41.216.189.133
23.95.90.77
160.80.97.229
30.141.64.67
159.100.254.186
18.192.213.182
38.6.177.226
18.183.19.253
36.91.103.194
3.21.143.255
39.105.8.126
35.157.245.45
23.21.80.20
18.222.52.181
4.246.214.148
34.93.210.165
25.62.225.236
38.132.114.172
3.97.251.201
23.94.230.178
159.75.148.67
38.6.177.94
3.141.142.211
182.135.42.23
159.203.125.55
159.100.245.70
182.92.216.171
38.12.36.53
39.98.201.125
31.7.61.18
4.37.94.98
183.131.85.64
39.104.200.45
185.17.115.238
27.25.140.14
38.6.179.130
26.81.134.145
182.204.180.148
159.100.253.166
23.224.239.103
159.75.101.155
3.18.247.131
185.130.46.229
23.95.243.30
23.95.243.24
23.95.243.25
23.95.243.26
23.95.243.27
23.95.243.20
159.89.204.231
23.95.243.21
23.95.243.22
23.95.243.23
24.137.215.159
206.123.132.163
23.95.243.28
3.248.199.103
23.95.243.29
158.247.250.154
27.189.30.46
34.126.174.34
39.108.248.6
38.6.190.15
4.158.105.167
38.6.216.13
38.6.177.42
18.176.57.203
159.75.132.99
39.98.250.47
159.223.219.19
23.224.239.77
23.95.243.18
23.95.243.19
222.186.148.121
38.91.113.74
185.106.176.168
183.176.135.22
38.60.253.183
36.52.45.78
16.171.241.158
38.47.101.176
38.92.40.83
38.6.164.159
27.105.178.16
18.233.73.116
23.95.233.140
40.124.112.232
3.91.137.53
3.79.67.90
42.193.53.74
34.136.92.127
35.189.217.151
34.248.124.89
39.100.111.77
38.54.30.122
35.220.155.114
37.197.57.116
34.120.16.137
16.163.146.197
202.79.172.198
192.210.216.212
159.65.56.30
3.31.238.78
41.163.25.137
39.106.86.126
23.227.198.50
38.45.126.242
4.218.17.135
38.242.198.230
185.18.222.235
39.105.51.11
39.100.109.229
39.100.101.55
156.251.17.59
42.194.196.215
34.231.255.33
3.130.13.22
161.123.69.29
38.147.171.167
23.95.190.180
23.95.190.181
222.137.196.209
3.135.98.249
38.165.10.240
39.102.213.159
23.133.216.223
39.100.79.152
38.54.2.165
23.94.141.249
3.84.14.21
38.55.184.82
23.95.190.179
23.95.190.178
34.225.7.112
159.75.166.183
18.191.219.171
3.86.13.34
3.27.133.113
23.95.47.68
26.139.162.71
38.128.251.227
23.224.61.73
23.95.190.188
23.95.190.189
23.95.181.149
23.95.190.186
23.95.181.148
23.95.190.187
23.95.181.147
23.95.190.184
23.95.181.146
23.95.190.185
23.95.190.182
23.95.190.183
39.96.33.178
18.132.148.106
39.103.236.200
38.6.155.8
157.230.15.195
34.41.72.142
185.18.222.24
38.47.106.176
41.63.30.50
39.100.132.142
18.168.221.150
185.56.204.242
159.100.250.203
185.254.37.80
35.189.178.127
222.77.177.198
182.119.140.169
18.144.30.84
158.160.167.13
35.177.233.199
182.92.238.31
23.224.61.90
3.27.12.150
157.173.197.177
3.127.59.75
3.142.167.4
35.240.151.120
156.236.69.114
156.238.229.79
221.226.155.132
4.180.40.69
3.131.200.234
37.10.71.215
37.60.242.25
18.169.194.5
38.54.17.210
36.139.139.199
38.180.82.154
39.102.210.162
24.125.22.205
24.48.65.15
42.194.184.161
4.185.109.49
39.107.242.125
3.107.99.94
35.198.215.60
3.127.190.89
38.45.65.195
42.51.34.223
218.93.155.39
39.104.18.200
157.230.110.191
184.54.46.2
158.101.167.230
23.94.200.249
39.98.37.146
37.27.11.209
42.193.117.162
23.22.218.218
157.245.14.245
3.126.224.214
23.95.248.194
18.167.125.209
201.230.41.171
3.127.133.106
35.91.159.178
34.215.75.141
34.69.83.199
3.231.153.226
23.95.248.199
3.27.222.163
35.240.206.123
39.106.36.26
23.95.248.195
34.92.215.227
23.95.248.196
34.199.66.228
223.113.128.179
113.225.168.82
【情报-漏洞预警】
【情报来源】:内部
【漏洞类型】:泛微 E-Cology 远程代码执行漏洞
漏洞危害】:高
【情报简述】
【漏洞详情】
【处置方法】:官方已发布最新版本修复
该漏洞,受影响客户请联
系厂商或自行下载最新补
丁包。下载链接:
S https://www.weaver.com
.cn/cs/securityDownloa
d.html?src=cn
临时措施:封堵该路径,等待厂商发布升级补丁。
【情报-漏洞预警】
【情报来源】:内部
【漏洞类型】:1Panel 面板前台 sql 注入漏洞(CVE-2024-39911)
【漏洞危害】
【情报简述】
【漏洞详情】
【处置方法】
临时措施:升级最新版本 少 1Panel-现代化、开源的 Linux 服务器运维管理面板。
【情报-漏洞预警】
【情报来源】:内部
【漏洞类型】:Alibaba Nacos derby 远程代码执行漏洞
【漏洞危害】:高
【情报简述】
【漏洞详情】
【处置方法】:
临时措施:封堵该路径,等待厂商发布升级补丁
【情报-漏洞预警】
【情报来源】:内部
【漏洞类型】:命令执行
【漏洞危害】:高
【情报简述】:关于浪潮云财务系统存在命令执行
【漏洞洋情】:近日安全运营中心收到漏洞预警情报,浪潮云财务系统路径/cwbaselgspwebsenvicelbizintegrationwebsenicelbizintegrationwebsenice,asmx存在命令执行
利用该漏洞可获取服务器控制权限。
【处置方法】:
临时措施:封堵该路径,等待厂商发布升级补丁。
【泛微一级安全通知】关于Ecology任意文件写入(RCE)漏洞的修复通知(注意:如部署有测试环境,测试环境也记得更新安全补丁包!)
泛微如下产品功能受以上漏洞影响:
1、Ecology8.0(必须升级到10.65版本安全补丁包)
2、Ecology9.0(目前安全补丁包,低于V10.62版本需要手工尽快升级)
升级方法:
方法1:等待安全包自动更新;
方法2:用sysadmin登录oa系统,访问/security/monitor/Monitorjsp,点击【环境信息】,如果看到【下载并应用更新】,可以直接点击,然后等待几分钟后即可实现在线更新,该更新不需要重启服务。
方法3:手工停止服务打包
【供应链厂商情报】奇安信天警存在0day漏洞
漏洞等级:
超危
漏洞描述:
奇安信天擎V10是一款终端安全软件,经供应链厂商反馈,该软件服务端存在0day漏洞,需增打安全补丁修复。
受影响产品(版本):
奇安信天擎V10服务端
目前纷传已更新漏洞如下:
2024-07-22总更新漏洞如下:
1. U8cloud系统MeasureQueryframeAction SQL注入漏洞 2. 用友 GRP-A-Cloud 政府财务云 selectGlaDatasourcePreview SQL注入漏洞 3. 北京致远互联软件股份有限公司AnalyticsCloud分析云存在任意文件读取漏洞
4. 蓝凌KEP前台RCE漏洞
6. 1Panel面板最新前台RCE漏洞(CVE-2024-39911)
7. SuiteCRM系统接口responseEntryPoint存在SQL注入漏洞(CVE-2024-36412)
8. Netgear-WN604接口downloadFile.php信息泄露漏洞(CVE-2024-6646)
9. Nacos远程代码执行漏洞
10. LiveNVR流媒体服务软件接口存在未授权访问漏洞 livenvr 青柿视频管理系统 channeltree 存在未授权访问漏洞
11. fogproject系统接口export.php存在远程命令执行漏洞(CVE-2024-39914)
12. 全息AI网络运维平台ajax_cloud_router_config.php存在命令执行漏洞
13. 广联达OA接口ArchiveWebService存在XML实体注入漏洞
14. 亿赛通数据泄露防护(DLP)系统NetSecConfigAjax SQL 注入 漏洞
15. 亿赛通数据泄露防护(DLP)系统 NoticeAjax SQL 注入漏洞
16. 用友CRM系统import.php任意文件上传漏洞
17. 用友GRP A++Cloud政府财务云存在任意文件读取漏洞
18. 瑞友天翼应用虚拟化系统hmrao.php存在SQL注入漏洞
19. 红海云eHR-PtFjk.mob存在任意文件上传漏洞
20. 福建科立讯通信指挥调度管理平台ajax_users.php存在SQL注入漏洞
21. 泛微OA E-Cology ln.FileDownload文件读取漏洞
22. 大华DSS数字监控系统存在SQL注入漏洞
原文始发于微信公众号(TeamSecret安全团队):【2024Hvv情报】日报总结
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论