当前位置:网站首页>Know that Chuangyu cloud monitoring - scanv Max update: Ecology OA unauthorized server request forgery and other two vulnerabilities can be detected
Know that Chuangyu cloud monitoring - scanv Max update: Ecology OA unauthorized server request forgery and other two vulnerabilities can be detected
2022-07-03 04:18:00 【Know Chuangyu kcsc】

This update ScanV MAX Vulnerability detection plug-in feature library to version :20220211
New vulnerability detection plug-in 2 individual , Optimize history plugin 7 individual
One 、 New vulnerability detection plug-in
1.Ecology OA Unauthorized server request forgery vulnerability , Plug in update time :2022 year 02 month 11 Japan
2.Microweber Information leak vulnerability (CVE-2022-0281), Plug in update time :2022 year 02 month 11 Japan
Vulnerability related information :
1.Ecology OA Unauthorized server request forgery vulnerability
Vulnerability plug-in update time :
2022 year 02 month 11 Japan
Vulnerability level :
Middle risk
Holes affect :
Pan Wei e-cology OA An unauthorized server request forgery vulnerability exists in an interface of the system , Unauthorized attackers can use this vulnerability to detect the intranet , Attack intranet system .
scope :
according to ZoomEye Cyberspace search engine keywords app:" Pan Wei Cooperative Office OA" Search for potential targets , Get... Together 28,160 strip IP Historical record . It is mainly distributed in China 、 The United States and other countries .
(ZoomEye Search for links :https://www.zoomeye.org/searchResult?q=app%3A%22%E6%B3%9B%E5%BE%AE%20%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%ACOA%22)

Global distribution :

Suggested solution :
The official has not fixed this vulnerability , Vulnerabilities can be temporarily URL Add access control , If there is no functional requirement, the interface file can be deleted .
2.Microweber Information leak vulnerability (CVE-2022-0281)
Vulnerability plug-in update time :
2022 year 02 month 11 Japan
The source of the leak :
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0281
Vulnerability level :
Middle risk
Holes affect :
Microweber 1.2.11 Information disclosure vulnerability exists in previous versions . An unauthorized attacker can use this vulnerability to obtain the accounts of all users of the system 、 Email and other information .
scope :
according to ZoomEye Cyberspace search engine keywords microweber Search for potential targets , Get... Together 20,221 strip IP Historical record . Mainly distributed in Bulgaria 、 The United States and other countries .
(ZoomEye Search for links :https://www.zoomeye.org/searchResult?q=microweber)

Global distribution :

Suggested solution :
The official has released an updated patch , Please download and update the affected customers to the safe version in time , Reference link :https://github.com/microweber/microweber
Reference link :
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0281
Two 、 Plug in optimization 7 individual
1、 Optimize “PHPUnit Remote code execution vulnerability ” Detection logic of plug-in , Reduce false alarm rate
2、 Optimize “Jira Unauthorized users enumerate vulnerabilities ” Scanning method of plug-in
3、 Optimize “WordPress DZS Zoomsounds Arbitrary file download vulnerability ” Detection method of plug-in
4、 Optimize “Jira Template injection Code Execution Vulnerability ” plug-in unit , Improve detection speed
5、 Optimize “Apache APISIX Dashboard Unauthorized access vulnerability ” The logical relationship of plug-ins , Reduce false alarm rate
6、 Optimize “GitLab ExifTool Remote command execution vulnerability ” plug-in unit , Improve detection speed
7、 Optimize “Openfire Server side Request Forgery vulnerability ” Detection method of plug-in
The above plug-ins are updated 、 The optimization comes from Chuangyu security intelligent brain big data analysis platform , The optimization and update made after the analysis of recent vulnerability utilization and utilization methods , Support at the same time WebSOC series .

if there be Relevant business requirements
Please scan Contact an expert for advice


Click on Read the original
Turn on ScanV MAX Multidimensional stereo monitoring
边栏推荐
- The longest subarray length with a positive product of 1567 recorded by leecode
- Js/ts bottom implementation double click event
- Supervised pre training! Another exploration of text generation!
- How to process the current cell with a custom formula in conditional format- How to address the current cell in conditional format custom formula?
- sd卡数据损坏怎么回事,sd卡数据损坏怎么恢复
- 220214c language learning diary
- leetcode:297. Serialization and deserialization of binary tree
- Mongodb slow query optimization analysis strategy
- [brush questions] connected with rainwater (one dimension)
- Basic MySQL operations
猜你喜欢

使用BENCHMARKSQL工具对KingbaseES预热数据时执行:select sys_prewarm(‘NDX_OORDER_2 ‘)报错

C language series - Section 3 - functions

When writing a web project, SmartUpload is used for file upload and new string () is used for transcoding, but in the database, there will still be random codes similar to poker

MPLS setup experiment
![[nlp] - brief introduction to the latest work of spark neural network](/img/65/35ae0137f4030bdb2b0ab9acd85e16.png)
[nlp] - brief introduction to the latest work of spark neural network

540. Single element in ordered array
![[dynamic programming] subsequence problem](/img/d8/020ae959ef53ce097d3a81a0d2d63a.jpg)
[dynamic programming] subsequence problem

Mila、渥太华大学 | 用SE(3)不变去噪距离匹配进行分子几何预训练

一名外包仔的2022年中总结

深潜Kotlin协程(十九):Flow 概述
随机推荐
Analysis of the reason why the server cannot connect remotely
CVPR 2022 | 大连理工提出自校准照明框架,用于现实场景的微光图像增强
[brush questions] find the number pair distance with the smallest K
金仓数据库KingbaseES 插件kdb_database_link
[Chongqing Guangdong education] reference materials for design and a better life of Zhongyuan Institute of science and technology
[Yu Yue education] reference materials of political communication science of Communication University of China
Introduction to eth
Deep dive kotlin synergy (19): flow overview
[set theory] set concept and relationship (true subset | empty set | complete set | power set | number of set elements | power set steps)
金仓数据库KingbaseES 插件kdb_date_function
2022-07-02: what is the output of the following go language code? A: Compilation error; B:Panic; C:NaN。 package main import “fmt“ func main() { var a =
[文献阅读] Sparsity in Deep Learning: Pruning and growth for efficient inference and training in NN
金仓数据库KingbaseES 插件kdb_exists_expand
Sklearn data preprocessing
DAPP for getting started with eth
服务器无法远程连接原因分析
The longest subarray length with a positive product of 1567 recorded by leecode
Basic types of data in TS
深潜Kotlin协程(二十):构建 Flow
【刷题篇】多数元素(超级水王问题)