当前位置:网站首页>Know that Chuangyu cloud monitoring - scanv Max update: Ecology OA unauthorized server request forgery and other two vulnerabilities can be detected
Know that Chuangyu cloud monitoring - scanv Max update: Ecology OA unauthorized server request forgery and other two vulnerabilities can be detected
2022-07-03 04:18:00 【Know Chuangyu kcsc】

This update ScanV MAX Vulnerability detection plug-in feature library to version :20220211
New vulnerability detection plug-in 2 individual , Optimize history plugin 7 individual
One 、 New vulnerability detection plug-in
1.Ecology OA Unauthorized server request forgery vulnerability , Plug in update time :2022 year 02 month 11 Japan
2.Microweber Information leak vulnerability (CVE-2022-0281), Plug in update time :2022 year 02 month 11 Japan
Vulnerability related information :
1.Ecology OA Unauthorized server request forgery vulnerability
Vulnerability plug-in update time :
2022 year 02 month 11 Japan
Vulnerability level :
Middle risk
Holes affect :
Pan Wei e-cology OA An unauthorized server request forgery vulnerability exists in an interface of the system , Unauthorized attackers can use this vulnerability to detect the intranet , Attack intranet system .
scope :
according to ZoomEye Cyberspace search engine keywords app:" Pan Wei Cooperative Office OA" Search for potential targets , Get... Together 28,160 strip IP Historical record . It is mainly distributed in China 、 The United States and other countries .
(ZoomEye Search for links :https://www.zoomeye.org/searchResult?q=app%3A%22%E6%B3%9B%E5%BE%AE%20%E5%8D%8F%E5%90%8C%E5%8A%9E%E5%85%ACOA%22)

Global distribution :

Suggested solution :
The official has not fixed this vulnerability , Vulnerabilities can be temporarily URL Add access control , If there is no functional requirement, the interface file can be deleted .
2.Microweber Information leak vulnerability (CVE-2022-0281)
Vulnerability plug-in update time :
2022 year 02 month 11 Japan
The source of the leak :
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0281
Vulnerability level :
Middle risk
Holes affect :
Microweber 1.2.11 Information disclosure vulnerability exists in previous versions . An unauthorized attacker can use this vulnerability to obtain the accounts of all users of the system 、 Email and other information .
scope :
according to ZoomEye Cyberspace search engine keywords microweber Search for potential targets , Get... Together 20,221 strip IP Historical record . Mainly distributed in Bulgaria 、 The United States and other countries .
(ZoomEye Search for links :https://www.zoomeye.org/searchResult?q=microweber)

Global distribution :

Suggested solution :
The official has released an updated patch , Please download and update the affected customers to the safe version in time , Reference link :https://github.com/microweber/microweber
Reference link :
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0281
Two 、 Plug in optimization 7 individual
1、 Optimize “PHPUnit Remote code execution vulnerability ” Detection logic of plug-in , Reduce false alarm rate
2、 Optimize “Jira Unauthorized users enumerate vulnerabilities ” Scanning method of plug-in
3、 Optimize “WordPress DZS Zoomsounds Arbitrary file download vulnerability ” Detection method of plug-in
4、 Optimize “Jira Template injection Code Execution Vulnerability ” plug-in unit , Improve detection speed
5、 Optimize “Apache APISIX Dashboard Unauthorized access vulnerability ” The logical relationship of plug-ins , Reduce false alarm rate
6、 Optimize “GitLab ExifTool Remote command execution vulnerability ” plug-in unit , Improve detection speed
7、 Optimize “Openfire Server side Request Forgery vulnerability ” Detection method of plug-in
The above plug-ins are updated 、 The optimization comes from Chuangyu security intelligent brain big data analysis platform , The optimization and update made after the analysis of recent vulnerability utilization and utilization methods , Support at the same time WebSOC series .

if there be Relevant business requirements
Please scan Contact an expert for advice


Click on Read the original
Turn on ScanV MAX Multidimensional stereo monitoring
边栏推荐
- Analysis of the reason why the server cannot connect remotely
- 300+ documents! This article explains the latest progress of multimodal learning based on transformer
- 金仓数据库KingbaseES 插件kdb_exists_expand
- When writing a web project, SmartUpload is used for file upload and new string () is used for transcoding, but in the database, there will still be random codes similar to poker
- 使用BENCHMARKSQL工具对kingbasees并发测试时kill掉主进程成功后存在子线程未及时关闭
- [文献阅读] Sparsity in Deep Learning: Pruning and growth for efficient inference and training in NN
- ZIP文件的导出
- [fairseq] 报错:TypeError: _broadcast_coalesced(): incompatible function arguments
- [pat (basic level) practice] - [simple simulation] 1063 calculate the spectral radius
- "Designer universe" argument: Data Optimization in the design field is finally reflected in cost, safety and health | chinabrand.com org
猜你喜欢

IPv6 foundation construction experiment
![[brush questions] most elements (super water king problem)](/img/79/13a715b74bc18a4a62113de76a65f6.png)
[brush questions] most elements (super water king problem)
![[fxcg] inflation differences will still lead to the differentiation of monetary policies in various countries](/img/56/386f0fd6553b8b9711e14c54705ae3.jpg)
[fxcg] inflation differences will still lead to the differentiation of monetary policies in various countries

深潜Kotlin协程(十九):Flow 概述

vulnhub HA: Natraj

JS实现图片懒加载

国产PC系统完成闭环,替代美国软硬件体系的时刻已经到来

Two points -leetcode-540 A single element in an ordered array

Causal AI, a new paradigm for industrial upgrading of the next generation of credible AI?

arthas watch 抓取入参的某个字段/属性
随机推荐
"Final review" 16/32-bit microprocessor (8086) basic register
MongoDB 慢查询语句优化分析策略
树莓派如何连接WiFi
Js/ts bottom implementation double click event
How do you use lodash linking function- How do you chain functions using lodash?
Causal AI, a new paradigm for industrial upgrading of the next generation of credible AI?
PostgreSQL database high availability Patroni source code learning - etcd class
Mongodb slow query optimization analysis strategy
[software testing-6] & Test Management
JS native common knowledge
Redraw and reflow
CVPR 2022 | Dalian Technology propose un cadre d'éclairage auto - étalonné pour l'amélioration de l'image de faible luminosité de la scène réelle
[brush questions] connected with rainwater (one dimension)
Basic MySQL operations
300+ documents! This article explains the latest progress of multimodal learning based on transformer
[fairseq] error: typeerror:_ broadcast_ coalesced(): incompatible function arguments
Introduction to eth
【刷题篇】接雨水(一维)
[home push IMessage] software installation virtual host rental tothebuddy delay
The latest activation free version of Omni toolbox