ÐÛÂõÔÆ·þÎñÆ÷ÄÚÖÃÓ²±àÂëÕË»§Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-10-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17919£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.1£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


º¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾XMeye P2PÔÆ·þÎñÆ÷
ËùÓÐͨ¹ýº¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾´ú¹¤µÄ»ùÓÚXMeye P2PÔÆ·þÎñÆ÷×°±¸


Îó²î¸ÅÊö


XMeye P2PÔÆ·þÎñÆ÷ÊÇÒ»ÖÖÓÃÓÚNVR/DVR×°±¸ÖÎÀíµÄ×é¼þ£¬Óɺ¼ÖÝÐÛÂõ¹«Ë¾Éú²ú¡£´Ë×é¼þ±»·¢Ã÷±£´æÄÚÖÃÓ²±àÂëµÄÕ˺Å£¬¿É±»Ô¶³Ìͨ¹ýWeb½çÃæµÇ¼´Ó¶øÊµÏÖ·ÇÊÚȨµÄ×°±¸ÖÎÀí£¬ËùÓÐʹÓôË×é¼þµÄ×°±¸¾ù´ËÇå¾²ÎÊÌâµÄÓ°Ï졣ͬʱװ±¸»¹±£´æÏÔ×ŵÄĿ¼±éÀúÎó²î£¬¹¥»÷Õß¿ÉÒÔ¶ÁȡϵͳÖеÄí§ÒâÎļþ£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎÊÌâ½øÒ»²½¿ØÖÆÏµÍ³»ñȡԶ³ÌÏÂÁîÖ´ÐеÄÄÜÁ¦¡£

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÖйúµØÇøÖÐÁÉÄþʡʹÓÃÓÃÊýÄ¿×î¶à£¬¹²ÓÐ4582̨£»¹ã¶«Ê¡µÚ¶þ£¬¹²ÓÐ1838̨£¬É½¶«Ê¡µÚÈý£¬¹²ÓÐ1566̨£¬±±¾©ÊеÚËÄ£¬¹²ÓÐ1492̨£¬½­ËÕÊ¡µÚÎ壬¹²ÓÐ1232̨¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP


1¡¢Í¨¹ýWebÖÎÀí½çÃæµÇ¼ÄÚÖÃÓ²±àÂëÕ˺Å
ͨ¹ýä¯ÀÀÆ÷Ö±½Ó»á¼ûurl£¬Ê¹ÓÃÓ²±àÂëÕË»§¼´¿ÉÖ±½ÓµÇ¼ÊÓÆµ¼à¿Ø½çÃæ¡£Ó²±àÂëÕË»§¼°¿ÚÁîΪ£ºdefault/¿Õ¿ÚÁî»òdefault/tluafed

ÈçÏÂÑÝʾ£º


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


µÇ¼½øÈëºóµÄÖÎÀíÒ³Ãæ£º


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


2¡¢ Web ServeĿ¼±éÀúÎó²î
XMeye P2PÔÆ·þÎñÆ÷Web Server×é¼þȨÏÞÉèÖò»µ±£¬µ¼Ö¿ÉÒÔ±éÀúĿ¼¶ÁÈ¡í§ÒâÎļþ¡£ÒÔÏÂÒÔʵÑé»á¼û/../../../../../procΪÀý¡£


ÈçÏÂͼ£º

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

ÐÞ¸´½¨Òé


×Ô²éÒªÁ죺
Éó²éXMeye P2PÔÆ·þÎñÆ÷×°±¸ÊÇ·ñ¿ªÆôWebÖÎÀí£¬²¢Ê¹ÓÃÄÚÖÃÕË»§ÔÚWebÖÎÀí½çÃæÊµÑéµÇ¼¡£ÈôÉϰ¶Àֳɣ¬ÔòÎó²î±£´æ¡£

Éý¼¶²¹¶¡£º
º¼ÖÝÐÛÂõÏÖÔÚ²¢Î´¾Í´ËÎó²îÐû²¼Èκβ¹¶¡£¬Ïà¹ØÊÜÓ°ÏìÓû§ÇëÁªÏµº¼ÖÝÐÛÂõ¿Æ¼¼¼°Ïà¹Ø³§ÉÌ»ñȡ֧³Ö¡£

ÔÝʱ´¦Öóͷ£²½·¥£º
1¡¢Ê¹Óð×Ãûµ¥·½·¨ÏÞÖÆ¿É»á¼ûWEBÖÎÀíÆ½Ì¨µÄȪԴIP»ò¹Ø±ÕWEBÖÎÀíÆ½Ì¨¡£
2¡¢ÍâµØÍ¨¹ý´®¿ÚÐÞ¸ÄÄÚÖõÄrootÕË»§¿ÚÁî¡£

²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06
http://www.xiongmaitech.com/