¹¥»÷ÕßÀûÓÃGhost CMS¸ßΣ·ì϶עÈë¶ñÒâ´úÂë
°ä²¼¹¦·ò 2026-05-251. ¹¥»÷ÕßÀûÓÃGhost CMS¸ßΣ·ì϶עÈë¶ñÒâ´úÂë
5ÔÂ24ÈÕ£¬£¬£¬£¬£¬Ò»³¡´ó¹æÄ£ÍøÂç¹¥»÷»î¶¯ÕýÀûÓÃGhostÄÚÈÝÖÎÀíϵͳ£¨CMS£©ÖеÄÒ»¸öÑϳÁSQL×¢Èë·ì϶£¨CVE-2026-26980£©£¬£¬£¬£¬£¬ÏòÖ¸±êÍøÕ¾×¢Èë¶ñÒâJavaScript´úÂ룬£¬£¬£¬£¬½ø¶ø´¥·¢ClickFix¹¥»÷Á÷³Ì¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìGhost 3.24.0ÖÁ6.19.0°æ±¾£¬£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß´ÓÍøÕ¾Êý¾Ý¿âÖжÁÈ¡ËÁÒâÊý¾Ý£¬£¬£¬£¬£¬Ô̺¬ÖÎÀíÔ±APIÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£Ò»µ©»ñµÃ¸ÃÃÜÔ¿£¬£¬£¬£¬£¬¹¥»÷Õß±ã¿ÉÕ¼ÓÐÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬½Ó¼ûÓû§¡¢ÎÄÕºÍÖ÷Ì⣬£¬£¬£¬£¬²¢´Û¸ÄÎÄÕÂÒ³Ãæ¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜGhost CMSÒÑÔÚ6.19.1°æ±¾ÖÐÓÚ2ÔÂ19ÈÕ°ä²¼½¨¸´²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬µ«´óÁ¿ÍøÕ¾Î´ÄÜʵʱ¸üУ¬£¬£¬£¬£¬µ¼Ö·ì϶±»¿í·ºÀûÓᣡ£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÒÑÓ°Ï쳬¹ý700¸öÓòÃû£¬£¬£¬£¬£¬Êܺ¦ÕßÔ̺¬´óѧÃÅ»§ÍøÕ¾¡¢ÈËΪÖÇÄÜÓëSaaS¹«Ë¾¡¢Ã½Ìå»ú¹¹¡¢½ðÈڿƼ¼¹«Ë¾¡¢°²È«ÍøÕ¾ÒÔ¼°Ó×ÎÒ²©¿Í¡£¡£¡£¡£¡£¡£¡£ÁîÈ˹Ø×¢µÄÊÇ£¬£¬£¬£¬£¬¹¥»÷ÕßÉõÖÁÔÚ¹þ·ð´óѧ¡¢Å£½ò´óѧ¡¢°Â±¾´óѧºÍDuckDuckGoµÈ³ÛÃû»ú¹¹µÄÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÖÁÉٹ۲쵽Á½¸ö·ÖÆçµÄ¹¥»÷»î¶¯¼¯Èº£¬£¬£¬£¬£¬ËüÃÇ»áÖØÎÂϰȾͳһÓòÃû£¬£¬£¬£¬£¬ÉõÖÁÔÚËãÕʺó³ÁÐÂ×¢Èë¾ç±¾£¬£¬£¬£¬£¬»òÕßÏ໥¸²¸Ç¶Ô·½µÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/
2. Laravel Lang°üÔâ´Û¸Ä£¬£¬£¬£¬£¬¹©¸øÁ´¹¥»÷ÇÔÈ¡¿ª·¢Õ߯¾Ö¤
5ÔÂ23ÈÕ£¬£¬£¬£¬£¬Ò»³¡Õë¶ÔLaravel Lang±¾µØ»¯°üµÄ¹©¸øÁ´¹¥»÷ÔÚ²úÉú£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÀÄÓÃGitHub°æ±¾±êǩְÄÜ£¬£¬£¬£¬£¬ÀûÓÃComposer°üÖÎÀíÆ÷·Ö·¢¶ñÒâ´úÂ룬£¬£¬£¬£¬Ê¹¿ª·¢ÕßÃæ¶Ô¸´Ôӵį¾Ö¤ÇÔÈ¡¶ñÒâÈí¼þÍþв¡£¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾StepSecurity¡¢Aikido SecurityºÍSocketÓÚ½üÈÕ·¢³öÖҸ棬£¬£¬£¬£¬³Æ¹¥»÷Õß´Û¸ÄÁËLaravel Lang×éÖ¯ÊØ»¤µÄËĸö´æ´¢¿âÖеÄGitHub±êÇ©£¬£¬£¬£¬£¬¶ø·Ç°ä²¼È«ÐµĶñÒâ°æ±¾¡£¡£¡£¡£¡£¡£¡£ÕâЩLaravel LangÈí¼þ°üÊǵÚÈý·½±¾µØ»¯°ü£¬£¬£¬£¬£¬²¢·ÇLaravel¹Ù·½ÏîÖ÷ÕÅÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄÌØÊâÖ®´¦ÔÚÓÚ£¬£¬£¬£¬£¬¹¥»÷Õß²¢Ã»ÓÐÅú¸ÄÏîÖ÷ÕÅÏÖʵԴ´úÂëÀ´Ôö³¤¶ñÒâ´úÂ룬£¬£¬£¬£¬¶øÊÇÀÄÓÃÁËGitHubµÄÒ»ÏîÖ°ÄÜ£¬£¬£¬£¬£¬¸ÃÖ°ÄÜÔÊÐí±êǩָÏòͳһ´æ´¢¿âÖÐ·ÖÆç·ÖÖ§µÄÌá½»¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß³ÁдÁËÿ¸ö´æ´¢¿âÖÐËùÓÐÏÖÓеÄgit±êÇ©£¬£¬£¬£¬£¬Ê¹ÆäÖ¸ÏòÒ»¸öеĶñÒâÌá½»£¬£¬£¬£¬£¬¶ø·Ç°ä²¼ÐµĶñÒâ°æ±¾¡£¡£¡£¡£¡£¡£¡£³Áд²Ù×÷´Ólaravel-lang/langÆðÍ·£¬£¬£¬£¬£¬µ½laravel-lang/actionsʵÏÖ£¬£¬£¬£¬£¬ËùÓÐËĸö²Ö¿â¾ùʹÓÃÁËÒ»ÑùµÄα×ö×÷ÕßÉí·Ý¡¢Ò»ÑùµÄÅú¸ÄÎļþºÍÒ»ÑùµÄÓÐÐ§ÔØºÉÐÐΪ£¬£¬£¬£¬£¬ÕâÏÕЩÄܹ»×¢¶¨ÊÇÓÉͳһ¹¥»÷ÕßʹÓÃÒ»¸ö±»µÁÓõġ¢ÓµÓÐ×éÖ¯¼¶ÍÆËÍȨÏÞµÄÆ¾Ö¤ËùΪ¡£¡£¡£¡£¡£¡£¡£¾ÝAikido³Æ£¬£¬£¬£¬£¬¹¥»÷ÕßÈëÇÖÁËÈý¸ö´æ´¢¿âÖеÄ233¸ö°æ±¾£¬£¬£¬£¬£¬¶øSocket°µÊ¾Ô¼Äª700¸öº¹Çà°æ±¾¿ÉÄÜÊܵ½ÁËÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/laravel-lang-packages-hijacked-to-deploy-credential-stealing-malware/
3. Òâ´óÀû·ÛËéCINEMAGOALµÁ°æÉú̬£¬£¬£¬£¬£¬ÖÂ3ÒÚÅ·ÔªËðʧ
5ÔÂ23ÈÕ£¬£¬£¬£¬£¬Òâ´óÀûµÐÔֳɹ¦·ÛËéÁËÒ»¸öÒÔCINEMAGOALÀûÓÃΪÖ÷ÌâµÄÖØ´óµÁ°æÉú̬ϵͳ¡£¡£¡£¡£¡£¡£¡£ÓëµäÐ͵ÄIPTV·þÎñÌṩÉÌ·ÖÆç£¬£¬£¬£¬£¬CINEMAGOAL²ÉÈ¡Á˸üΪÒñ±ÎµÄÔË×÷·½Ê½£¬£¬£¬£¬£¬Ëü²»½øÐй«¿ªÓªÏú£¬£¬£¬£¬£¬¶øÊÇͨ¹ýÓû§×ÔÐÐ×°ÖõÄÀûÓ÷¨Ê½À´ÊµÏÖµÁ°æ½Ó¼û¡£¡£¡£¡£¡£¡£¡£ÔÚ´úºÅΪ¡°Tutto Chiaro¡±µÄ´ó¹æÄ£·´µÁ°æÐж¯ÖУ¬£¬£¬£¬£¬Òâ´óÀû½ðÈÚ¾¯Ô±¶ÓÁÐÔÚÈ«¹úÁìÓòÄÚÖ´ÐÐÁË100´ÎËѲ飬£¬£¬£¬£¬²é»ñÁË´óÁ¿ÓÐÖúÓÚ¼ø±ðÉæ°¸ÈËÔ±¼°È·¶¨·¸·¨ËùµÃµÄ¹Ø¼ü×ÊÁÏ¡£¡£¡£¡£¡£¡£¡£CINEMAGOALµÄÔË×÷»úÔ켫¾ß¼¼ÊõÏȽøÐÔ¡£¡£¡£¡£¡£¡£¡£¸ÃÀûÓÃÖ±½ÓÏνӵ½ºÏ·¨µÄÁ÷ýÌåÆ½Ì¨£¬£¬£¬£¬£¬Ê¹Óôӹú±í·þÎñÆ÷»ñÈ¡µÄÓÐЧ½âÃÜ´úÂë½øÐÐÉí·ÝÑéÖ¤¡£¡£¡£¡£¡£¡£¡£ÏµÍ³ÀûÓÃλÓÚÒâ´óÀû¾³ÄÚµÄÐé¹¹»ú£¬£¬£¬£¬£¬Ã¿Èý·ÖÖӴӺϷ¨¶©ÔÄÖв¶»ñÓÐЧµÄÉí·ÝÑéÖ¤ºÍ½âÃÜ´úÂ룬£¬£¬£¬£¬¶øºó³Áзַ¢¸ø¿Í»§¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬ÕâЩºÏ·¨¶©ÔľùʹÓÃÐéαÉí·ÝÐÅÏ¢ÔÚSky¡¢DAZN¡¢Netflix¡¢Disney+ºÍSpotifyµÈƽ̨ÉÏ¿ªÃ÷¡£¡£¡£¡£¡£¡£¡£Ó봫ͳµÄµÁ°æÁ÷ýÌå·ÖÆç£¬£¬£¬£¬£¬CINEMAGOAL²»½öÈÆ¹ýÁËÆ½Ì¨µÄ°²È«¹Ø±Õ£¬£¬£¬£¬£¬»¹ÌṩÁ˸üÓÅÖʵÄÅÔ¹ÛÂÄÀú£¬£¬£¬£¬£¬Óû§Ö±½Ó´ÓÔ·þÎñÅÔ¹ÛÄÚÈݶø·Ç½Ó¹ÜÁÓÖʵÁ°æÁ÷£¬£¬£¬£¬£¬Í¬Ê±ÏµÍ³¸²¸ÇÁËÓû§µÄÕæÊµIPµØÖ·£¬£¬£¬£¬£¬´ó´ó½µµÍÁ˱»À¹½ØµÄ¿ÉÄÜÐÔ¡£¡£¡£¡£¡£¡£¡£¾Ý¹À¼Æ£¬£¬£¬£¬£¬¸ÃµÁ°æÉú̬ÔÚÆäÔËÓªÆÚ¼äÔì³ÉµÄδ¸¶¶©ÔÄÊÕÈëËðʧԼΪ3ÒÚÅ·Ôª¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/legal/italy-disrupts-cinemagoal-piracy-app-that-stole-streaming-auth-codes/
4. ¼ÓÄÐ×ÓÔËÓª200Íǫ̀É豸½©Ê¬ÍøÂ磬£¬£¬£¬£¬ÔâÃÀ¼Ó½áºÏ¿ÛÁô
5ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úºÍ¼ÓÄô󵱾ֽüÈÕ¿ÛÁô²¢Ö¸¿ØÒ»Ãû23ËêµÄ¼ÓÄôóÄÐ×ÓÑŸ÷²¼¡¤°ÍÌØÀÕ£¨ÍøÃû¡°¶àÌØ¡±£©£¬£¬£¬£¬£¬×ïÃûÊÇÔËÓªÃûΪKimWolfµÄÉ¢²¼Ê½»Ø¾ø·þÎñ£¨DDoS£©½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç¹æÄ£¾ªÈË£¬£¬£¬£¬£¬Ï°È¾ÁËÈ«Çò½ü200Íǫ̀É豸¡£¡£¡£¡£¡£¡£¡£°ÍÌØÀÕÓÚÖÜÈýÔÚä×Ì«»ª±»¼ÓÄÃ´óµ±¾ÖÆ¾¾ÝÒý¶ÉÁî¿ÛÁô£¬£¬£¬£¬£¬Ä¿Ç°ÕýÆÚ´ý±»Òý¶ÉÖÁÃÀ¹ú¡£¡£¡£¡£¡£¡£¡£ËûÃæ¶ÔÒ»ÏîÐÖúºÍÖ§Ê¹ÍÆËã»úÈëÇÖµÄÖ¸¿Ø£¬£¬£¬£¬£¬×î¸ß¿ÉÅд¦10Äê½ûïÀ¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý°¢À˹¼ÓµØÓò°ä²¼µÄÐÌÊÂËß×´£¬£¬£¬£¬£¬·¨Âɲ¿ÃÅͨ¹ýIPµØÖ·¡¢ÔÚÏßÕË»§ÐÅÏ¢¡¢ÂòÂô¼Í¼ºÍÔÚÏßÐÂÎżÍ¼£¬£¬£¬£¬£¬³É¹¦½«°ÍÌØÀÕÓëKimWolf½©Ê¬ÍøÂçÁªÏµÆðÀ´¡£¡£¡£¡£¡£¡£¡£KimWolfÏÖʵÉÏÊÇÒ»¸öDDoS¹¥»÷³ö×â·þÎñƽ̨£¬£¬£¬£¬£¬±»ÍøÂç·¸×ï·Ö×ÓÓÃÀ´ÌáÒ鹿ģ¿£¿£¿£¿£¿£¿£¿ÕǰµÄ¹¥»÷£¬£¬£¬£¬£¬×î¸ß¹¥»÷Á÷Á¿¿¿½üÿÃë30Ì«±ÈÌØ£¬£¬£¬£¬£¬ÊÇÆäʱ¹«¿ªÅû¶µÄ×î´ó¹æÄ£DDoS¹¥»÷Ö®Ò»¡£¡£¡£¡£¡£¡£¡£°ÍÌØÀÕÑ¡È¡ÍøÂç·¸×ï¼´·þÎñģʽ£¬£¬£¬£¬£¬Ïò¿Í»§ÏúÊÛ¶ÔÖØ´óÊÜ¿ØÉè±¸ÍøÂçµÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£ÕâЩ±»Ï°È¾µÄÉ豸ÖÖÀà·±¶à£¬£¬£¬£¬£¬Ô̺¬ÊýÂëÏà¿ò¡¢ÍøÂçÉãÏñÍ·¡¢»ùÓÚ°²×¿ÏµÍ³µÄµçÊӺкÍÁ÷ýÌåÉ豸µÈÎïÁªÍøÖÕ¶Ë¡£¡£¡£¡£¡£¡£¡£¸Ã½©Ê¬ÍøÂç±»ÓÃÓÚ¶ÔÈ«ÇòÍÆËã»úºÍ·þÎñÆ÷ÌáÒ鳬¹ý25,000´Î¹¥»÷£¬£¬£¬£¬£¬¹¥»÷Ö¸±êÉõÖÁÔ̺¬ÃÀ¹ú¹ú·À²¿ÐÅÏ¢ÍøÂçµÄIPµØÖ·£¬£¬£¬£¬£¬¸ø²¿ÃÅÊܺ¦ÕßÔì³ÉÁ˳¬¹ý100ÍòÃÀÔªµÄ¾¼ÃËðʧ¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/us-and-canada-arrest-and-charge-suspected-kimwolf-botnet-admin/
5. Ç÷Ïò¿Æ¼¼½¨¸´ÒÑÔâÀûÓõÄApex OneÁãÈÕ·ì϶
5ÔÂ22ÈÕ£¬£¬£¬£¬£¬ÈÕ±¾ÍøÂ簲ȫÈí¼þ¹«Ë¾Ç÷Ïò¿Æ¼¼Òѽ¨¸´ÁËÒ»¸öÕë¶ÔÆäWindows°æApex OneÖն˰²È«Æ½Ì¨µÄÁãÈÕ·ì϶£¬£¬£¬£¬£¬¸Ã·ì϶Òѱ»·¢´Ë¿ÌÏÖʵ»·¾³ÖÐÔâµ½¹¥»÷ÀûÓᣡ£¡£¡£¡£¡£¡£Apex OneÊÇÇ÷Ïò¿Æ¼¼µÄÆóÒµ¼¶Öն˰²È«Æ½Ì¨£¬£¬£¬£¬£¬ÓÃÓÚ±£»£»£»£»£»£»£»¤ÆóÒµÍøÂçÃâÊܶñÒâÈí¼þ¡¢ÀÕË÷Èí¼þ¡¢ÎÞÎļþ¹¥»÷ºÍ»ùÓÚWebµÄÍþвµÈ¶àÖÖ°²È«Íþв¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±àºÅΪCVE-2026-34926£¬£¬£¬£¬£¬ÊÇÒ»¸ö´æÔÚÓÚApex One±¾µØ²¿Êð·þÎñÆ÷ÖеÄĿ¼±éÀú·ì϶£¬£¬£¬£¬£¬ÔÊÐíÓµÓÐÖÎÀíԱȨÏ޵ı¾µØ¹¥»÷Õß×¢Èë¶ñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¾ÝÇ÷Ïò¿Æ¼¼ÖÜËÄÅû¶£¬£¬£¬£¬£¬¸ÃĿ¼±éÀú·ì϶¿ÉÄÜÔÊÐíÔ¤ÏȾ¹ýÉí·ÝÑéÖ¤µÄ±¾µØ¹¥»÷ÕßÅú¸Ä·þÎñÆ÷ÉϵÄÃÜÔ¿±í£¬£¬£¬£¬£¬´Ó¶ø×¢Èë¶ñÒâ´úÂë²¢½«Æä²¿Êðµ½ÊÜÓ°Ïì×°ÖÃÖеĴúÀíÉÏ¡£¡£¡£¡£¡£¡£¡£±ØÒª×¢Ã÷µÄÊÇ£¬£¬£¬£¬£¬´Ë·ì϶½ö¿ÉÔÚApex OneµÄ±¾µØ²¿Êð°æ±¾ÉÏÀûÓ㬣¬£¬£¬£¬Ç±ÔÚ¹¥»÷Õß±ØÐëÕ¼ÓжÔApex One·þÎñÆ÷µÄ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬²¢ÇÒÒѾͨ¹ýÆäËû·½Ê½»ñµÃÁË·þÎñÆ÷µÄÖÎÀíÍ´´¦¡£¡£¡£¡£¡£¡£¡£Ö»¹Ü³É¹¦ÀûÓø÷ì϶µÄǰÌáÏ൱Ñϸñ£¬£¬£¬£¬£¬µ«Ç÷Ïò¿Æ¼¼ÖÒ¸æ³Æ£¬£¬£¬£¬£¬ÆäÍþвµý±¨ÏµÍ³¡°TrendAI¡±ÒѾ¹Û²ìµ½ÖÁÉÙһ·ÔÚÏÖʵ»·¾³ÖÐÀûÓø÷ì϶µÄ³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£¼øÓڸ÷ì϶Òѱ»»îÔ¾ÀûÓ㬣¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©ÓÚ×òÈÕ½«CVE-2026-34926ÄÉÈëÆäÔÚ±»ÀûÓõķì϶ÁÐ±í£¬£¬£¬£¬£¬²¢ºÅÁîÁª¹ú»ú¹¹ÔÚ6ÔÂ4ÈÕ֮ǰʵÏÖÉ豸½¨²¹¡£¡£¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/
6. Drupal SQL×¢Èë·ì϶(CVE-2026-9082)Ôâ´ó¹æÄ£ÀûÓÃ
5ÔÂ24ÈÕ£¬£¬£¬£¬£¬ÃÀ¹úÍøÂ簲ȫºÍ»ù´¡ÉèÊ©°²È«¾Ö£¨CISA£©Òѽ«Microsoft Exchange ServerÖеÄÒ»¸ö·ì϶£¨±àºÅCVE-2026-9082£¬£¬£¬£¬£¬CVSSÆÀ·Ö9.8£©Ôö³¤µ½ÆäÒÑÖªÀûÓ÷ì϶£¨KEV£©Ä¿Â¼ÖÓ×£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÏÖʵÉÏÊÇDrupalÓÚ5ÔÂ20ÈÕ°ä²¼¸ß¶È¹Ø¼ü°²È«²¹¶¡ËùÕë¶ÔµÄSQL×¢Èë·ì϶£¬£¬£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÈëÇÖÔËÐÐPostgreSQLÊý¾Ý¿âµÄÍøÕ¾¡£¡£¡£¡£¡£¡£¡£·ì϶ÀûÓÃÏÕЩÔÚ²¹¶¡°ä²¼ºóÁ¢¼´ÆðÍ·£¬£¬£¬£¬£¬48Ó×ʱÄÚ°²È«¹«Ë¾¾Í×·×Ùµ½ÁËÊýǧÆðÏÖʵ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚÒ»¸öÖ¼ÔÚËãÕÊÊý¾Ý¿â²éÎʲ¢Ô¤·ÀSQL×¢ÈëµÄAPIÖÓ×£¡£¡£¡£¡£¡£¡£¸ÃAPIµÄȱµãÒâζ׏¥»÷ÕßÄܹ»·¢ËÍÌØÔìÒªÇ󣬣¬£¬£¬£¬ÏòʹÓÃPostgreSQLµÄÍøÕ¾×¢ÈëËÁÒâSQLºÅÁî¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝDrupal°ä²¼µÄ°²È«²¼¸æ£¬£¬£¬£¬£¬´Ë·ì϶ÔÊÐí¹¥»÷Õßµ¼ÖÂʹÓÃPostgreSQLÊý¾Ý¿âµÄÍøÕ¾Ôâ·êËÁÒâSQL×¢Èë¹¥»÷£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÐÅϢй¶£¬£¬£¬£¬£¬ÔÚijЩÇé¿öÏ»¹»áÒý·¢È¨ÏÞÌáÉý¡¢Ô¶³Ì´úÂëÖ´ÐлòÆäËû¹¥»÷¡£¡£¡£¡£¡£¡£¡£¸üÁîÈËÓÇÓôµÄÊÇ£¬£¬£¬£¬£¬ÄäÃûÓû§Ò²Äܹ»ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£5ÔÂ22ÈÕ¸üÐµİ²È«²¼¸æÈ·ÈÏ£¬£¬£¬£¬£¬·çÏÕÆÀ·ÖÒѸüÐÂÒÔ·´Ó³Ä¿Ç°ÒÑÔÚÏÖʵ»·¾³Öмì²âµ½¹¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£°²È«¹«Ë¾ImpervaÔÚ·ì϶Åû¶ºóµÄÁ½ÌìÄÚ£¬£¬£¬£¬£¬¼à²âµ½Õë¶Ô65¸ö¹ú¶È½ü6000¸öDrupalÍøÕ¾µÄ³¬¹ý15000´Î¹¥»÷³¢ÊÔ¡£¡£¡£¡£¡£¡£¡£½üÒ»°ëµÄ¹¥»÷Ö¸±ê¼¯ÖÐÔÚÓÎÏ·ºÍ½ðÈÚ·þÎñ»ú¹¹£¬£¬£¬£¬£¬Õâ¿ÉÄÜÊÇÓÉÓÚÕâЩ»ú¹¹µÄƾ֤ºÍ²ÆÕþÊý¾Ý¼ÛÖµ½Ï¸ß¡£¡£¡£¡£¡£¡£¡£
https://securityaffairs.com/192566/uncategorized/u-s-cisa-adds-a-flaw-in-drupal-core-to-its-known-exploited-vulnerabilities-catalog.html


¾©¹«Íø°²±¸11010802024551ºÅ