当前位置:网站首页>Know that Chuangyu cloud monitoring - scanv Max update: Ecology OA unauthorized server request forgery and other two vulnerabilities can be detected
Know that Chuangyu cloud monitoring - scanv Max update: Ecology OA unauthorized server request forgery and other two vulnerabilities can be detected
2022-07-03 04:18:00 【Know Chuangyu kcsc】

This update ScanV MAX Vulnerability detection plug-in feature library to version :20220211
New vulnerability detection plug-in 2 individual , Optimize history plugin 7 individual
One 、 New vulnerability detection plug-in
1.Ecology OA Unauthorized server request forgery vulnerability , Plug in update time :2022 year 02 month 11 Japan
2.Microweber Information leak vulnerability (CVE-2022-0281), Plug in update time :2022 year 02 month 11 Japan
Vulnerability related information :
1.Ecology OA Unauthorized server request forgery vulnerability
Vulnerability plug-in update time :
2022 year 02 month 11 Japan
Vulnerability level :
Middle risk
Holes affect :
Pan Wei e-cology OA An unauthorized server request forgery vulnerability exists in an interface of the system , Unauthorized attackers can use this vulnerability to detect the intranet , Attack intranet system .
scope :
according to ZoomEye Cyberspace search engine keywords app:" Pan Wei Cooperative Office OA" Search for potential targets , Get... Together 28,160 strip IP Historical record . It is mainly distributed in China 、 The United States and other countries .
(ZoomEye Search for links :https://www.zoomeye.org/searchResult?q=app%3A%22%E6%B3%9B%E5%BE%AE%20%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%ACOA%22)

Global distribution :

Suggested solution :
The official has not fixed this vulnerability , Vulnerabilities can be temporarily URL Add access control , If there is no functional requirement, the interface file can be deleted .
2.Microweber Information leak vulnerability (CVE-2022-0281)
Vulnerability plug-in update time :
2022 year 02 month 11 Japan
The source of the leak :
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0281
Vulnerability level :
Middle risk
Holes affect :
Microweber 1.2.11 Information disclosure vulnerability exists in previous versions . An unauthorized attacker can use this vulnerability to obtain the accounts of all users of the system 、 Email and other information .
scope :
according to ZoomEye Cyberspace search engine keywords microweber Search for potential targets , Get... Together 20,221 strip IP Historical record . Mainly distributed in Bulgaria 、 The United States and other countries .
(ZoomEye Search for links :https://www.zoomeye.org/searchResult?q=microweber)

Global distribution :

Suggested solution :
The official has released an updated patch , Please download and update the affected customers to the safe version in time , Reference link :https://github.com/microweber/microweber
Reference link :
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0281
Two 、 Plug in optimization 7 individual
1、 Optimize “PHPUnit Remote code execution vulnerability ” Detection logic of plug-in , Reduce false alarm rate
2、 Optimize “Jira Unauthorized users enumerate vulnerabilities ” Scanning method of plug-in
3、 Optimize “WordPress DZS Zoomsounds Arbitrary file download vulnerability ” Detection method of plug-in
4、 Optimize “Jira Template injection Code Execution Vulnerability ” plug-in unit , Improve detection speed
5、 Optimize “Apache APISIX Dashboard Unauthorized access vulnerability ” The logical relationship of plug-ins , Reduce false alarm rate
6、 Optimize “GitLab ExifTool Remote command execution vulnerability ” plug-in unit , Improve detection speed
7、 Optimize “Openfire Server side Request Forgery vulnerability ” Detection method of plug-in
The above plug-ins are updated 、 The optimization comes from Chuangyu security intelligent brain big data analysis platform , The optimization and update made after the analysis of recent vulnerability utilization and utilization methods , Support at the same time WebSOC series .

if there be Relevant business requirements
Please scan Contact an expert for advice


Click on Read the original
Turn on ScanV MAX Multidimensional stereo monitoring
边栏推荐
- [fxcg] market analysis today
- Solve BP Chinese garbled code
- The time has come for the domestic PC system to complete the closed loop and replace the American software and hardware system
- Basic types of data in TS
- 【刷题篇】多数元素(超级水王问题)
- Square root of X
- js实现在可视区内,文字图片动画效果
- Drf--- quick start 01
- [mathematical logic] predicate logic (judge whether the first-order predicate logic formula is true or false | explain | example | predicate logic formula type | forever true | forever false | satisfi
- Js/ts bottom implementation double click event
猜你喜欢

Redis persistence principle

Nodejs Foundation: shallow chat URL and querystring module

Deep dive kotlin synergy (19): flow overview

金仓KFS数据双向同步场景部署

Arduino application development - LCD display GIF dynamic diagram
![[graduation season · aggressive technology Er] Confessions of workers](/img/ec/4f4d96e22a1029074b07ab80bfa1d9.png)
[graduation season · aggressive technology Er] Confessions of workers

js实现在可视区内,文字图片动画效果

300+ documents! This article explains the latest progress of multimodal learning based on transformer

Basic MySQL operations

MPLS setup experiment
随机推荐
Which Bluetooth headset is good about 400? Four Bluetooth headsets with strong noise reduction are recommended
Interface in TS
2.14 simulation summary
多板块轮动策略编写技巧----策略编写学习教材
类的基础语法
Mila, University of Ottawa | molecular geometry pre training with Se (3) invariant denoising distance matching
What is the correct way to compare ntext columns with constant values- What's the right way to compare an NTEXT column with a constant value?
【刷题篇】 找出第 K 小的数对距离
Export of zip file
[mathematical logic] predicate logic (predicate logic basic equivalent | eliminate quantifier equivalent | quantifier negative equivalent | quantifier scope contraction expansion equivalent | quantifi
MPLS setup experiment
Square root of X
深潜Kotlin协程(十九):Flow 概述
[brush questions] find the number pair distance with the smallest K
[dynamic programming] subsequence problem
使用BENCHMARKSQL工具对KingbaseES执行测试时报错funcs sh file not found
xrandr修改分辨率與刷新率
Redraw and reflow
金仓KFS数据双向同步场景部署
Classes in TS