ÐÛÂõÔÆÐ§ÀÍÆ÷ÄÚÖÃÓ²±àÂëÕË»§Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2018-10-17

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2018-17919£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ8.1£¬£¬£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


º¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾XMeye P2PÔÆÐ§ÀÍÆ÷
ËùÓÐͨ¹ýº¼ÖÝÐÛÂõ¿Æ¼¼ÓÐÏÞ¹«Ë¾´ú¹¤µÄ»ùÓÚXMeye P2PÔÆÐ§ÀÍÆ÷×°±¸


Îó²î¸ÅÊö


XMeye P2PÔÆÐ§ÀÍÆ÷ÊÇÒ»ÖÖÓÃÓÚNVR/DVR×°±¸ÖÎÀíµÄ×é¼þ£¬£¬£¬£¬£¬£¬Óɺ¼ÖÝÐÛÂõ¹«Ë¾Éú²ú¡£¡£¡£¡£´Ë×é¼þ±»·¢Ã÷±£´æÄÚÖÃÓ²±àÂëµÄÕ˺Å£¬£¬£¬£¬£¬£¬¿É±»Ô¶³Ìͨ¹ýWeb½çÃæµÇ¼´Ó¶øÊµÏÖ·ÇÊÚȨµÄ×°±¸ÖÎÀí£¬£¬£¬£¬£¬£¬ËùÓÐʹÓôË×é¼þµÄ×°±¸¾ù´ËÇå¾²ÎÊÌâµÄÓ°Ïì¡£¡£¡£¡£Í¬Ê±×°±¸»¹±£´æÏÔ×ŵÄĿ¼±éÀúÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ¶ÁȡϵͳÖеÄí§ÒâÎļþ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÎÊÌâ½øÒ»²½¿ØÖÆÏµÍ³»ñȡԶ³ÌÏÂÁîÖ´ÐеÄÄÜÁ¦¡£¡£¡£¡£

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÖйúµØÇøÖÐÁÉÄþʡʹÓÃÓÃÊýÄ¿×î¶à£¬£¬£¬£¬£¬£¬¹²ÓÐ4582̨£»£»£»£»£»£»¹ã¶«Ê¡µÚ¶þ£¬£¬£¬£¬£¬£¬¹²ÓÐ1838̨£¬£¬£¬£¬£¬£¬É½¶«Ê¡µÚÈý£¬£¬£¬£¬£¬£¬¹²ÓÐ1566̨£¬£¬£¬£¬£¬£¬±±¾©ÊеÚËÄ£¬£¬£¬£¬£¬£¬¹²ÓÐ1492̨£¬£¬£¬£¬£¬£¬½­ËÕÊ¡µÚÎ壬£¬£¬£¬£¬£¬¹²ÓÐ1232̨¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC\EXP


1¡¢Í¨¹ýWebÖÎÀí½çÃæµÇ¼ÄÚÖÃÓ²±àÂëÕ˺Å
ͨ¹ýä¯ÀÀÆ÷Ö±½Ó»á¼ûurl£¬£¬£¬£¬£¬£¬Ê¹ÓÃÓ²±àÂëÕË»§¼´¿ÉÖ±½ÓµÇ¼ÊÓÆµ¼à¿Ø½çÃæ¡£¡£¡£¡£Ó²±àÂëÕË»§¼°¿ÚÁîΪ£ºdefault/¿Õ¿ÚÁî»òdefault/tluafed

ÈçÏÂÑÝʾ£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


µÇ¼½øÈëºóµÄÖÎÀíÒ³Ãæ£º


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


2¡¢ Web ServeĿ¼±éÀúÎó²î
XMeye P2PÔÆÐ§ÀÍÆ÷Web Server×é¼þȨÏÞÉèÖò»µ±£¬£¬£¬£¬£¬£¬µ¼Ö¿ÉÒÔ±éÀúĿ¼¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£¡£ÒÔÏÂÒÔʵÑé»á¼û/../../../../../procΪÀý¡£¡£¡£¡£


ÈçÏÂͼ£º

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾

ÐÞ¸´½¨Òé


×Ô²éÒªÁ죺
Éó²éXMeye P2PÔÆÐ§ÀÍÆ÷×°±¸ÊÇ·ñ¿ªÆôWebÖÎÀí£¬£¬£¬£¬£¬£¬²¢Ê¹ÓÃÄÚÖÃÕË»§ÔÚWebÖÎÀí½çÃæÊµÑéµÇ¼¡£¡£¡£¡£ÈôÉϰ¶Àֳɣ¬£¬£¬£¬£¬£¬ÔòÎó²î±£´æ¡£¡£¡£¡£

Éý¼¶²¹¶¡£¡£¡£¡£º
º¼ÖÝÐÛÂõÏÖÔÚ²¢Î´¾Í´ËÎó²îÐû²¼Èκβ¹¶¡£¬£¬£¬£¬£¬£¬Ïà¹ØÊÜÓ°ÏìÓû§ÇëÁªÏµº¼ÖÝÐÛÂõ¿Æ¼¼¼°Ïà¹Ø³§ÉÌ»ñȡ֧³Ö¡£¡£¡£¡£

ÔÝʱ´¦Öóͷ£²½·¥£º
1¡¢Ê¹Óð×Ãûµ¥·½·¨ÏÞÖÆ¿É»á¼ûWEBÖÎÀíÆ½Ì¨µÄȪԴIP»ò¹Ø±ÕWEBÖÎÀíÆ½Ì¨¡£¡£¡£¡£
2¡¢ÍâµØÍ¨¹ý´®¿ÚÐÞ¸ÄÄÚÖõÄrootÕË»§¿ÚÁî¡£¡£¡£¡£

²Î¿¼Á´½Ó


https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06
http://www.xiongmaitech.com/