AI智能总结
目录 1. 概述.....................................................................................................................................................................52. 漏洞详情........................................................................................................................................................... 62.1 禅道项目管理系统身份认证绕过漏洞........................................................................................ 62.2Primeton EOS Platform jmx反序列化致远程代码执行漏洞....................................... 72.3IP-guard WebServer权限绕过漏洞........................................................................................ 82.4 泛微E-Office10反序列化漏洞................................................................................................... 82.5Jenkins任意文件读取漏洞.......................................................................................................... 92.6 用友YonBIP ServiceDispatcher远程代码执行漏洞.................................................... 102.7 亿赛通电子文档安全管理系统 远程代码执行漏洞...........................................................112.8GitLab任意用户密码重置漏洞.................................................................................................122.9kkFileView zipslip远程代码执行漏洞................................................................................ 132.10Palo Alto Networks PAN-OS命令注入漏洞...................................................................142.11 用友NC registerServlet反序列化远程代码执行漏洞................................................ 152.12 亿赛通电子文档安全管理系统hiddenWatermark/uploadFile文件上传漏洞.162.13Atlassian Confluence template/aui/text-inline.vm代码执行漏洞.....................172.14 亿赛通电子文档安全管理系统AutoSignService1接口远程代码执行漏洞....... 182.15 亿赛通电子文档安全管理系统CDG AuthoriseTempletService1接口远程代码执行漏洞...................................................................................................................................................... 192.16 堡塔云WAF get_site_status路径server_name参数SQL注入漏洞............. 202.17Weblogic ForeignOpaqueReference远程代码执行漏洞(CVE-2024-20931)......................................................................................................................................................................... 212.18 飞鱼星企业级智能上网行为管理系统/send_order.cgi?parameter=operation命令执行漏洞............................................................................................................................................. 222.19 畅捷通T+ /tplus/UFAQD/InitServerInfo.aspx SQL注入漏洞..............................232.20D-Link NAS /cgi-bin/nas_sharing.cgi命令执行漏洞................................................232.21 致远互联FE /sysform/003/editflow_manager.jsp SQL注入漏洞...................... 242.22Jeecg /api/../commonController.do文件 文件上传漏洞........................................252.23 锐捷RG-EW1200G /api/sys/login权限绕过漏洞........................................................ 262.24 畅捷通T+ /tplus/UFAQD/KeyInfoList.aspx SQL注入漏洞...................................272.25Fortinet FortiOS代码执行漏洞........................................................................................... 282.26 Jeecg jeecgFormDemoController JNDI 代码执行漏洞................................................ 292.27金蝶Apusic loadTree存在JNDI注入............................................................................... 302.28金蝶Apusic deployApp任意文件上传漏洞.....................................................................312.29Apache Struts2目录遍历漏洞..............................................................................................312.30 金蝶云星空/ScpSupRegHandler路径存在任意文件上传漏洞.............................. 322.31Atlassian Confluence远程代码执行漏洞....................................................................... 332.32 F5 BIG-IP TMUI 远程代码执行漏洞.....................................................................................342.33Apache ActiveMQ服务端口 远程代码执行漏洞.......................................................... 352.34 金山终端安全系统V9.0 SQL注入漏洞.............................................................................. 362.35 金蝶EAS /myUploadFile.do路径存在任意文件上传漏洞........................................372.36Citrix ADC & Citrix Gateway会话令牌泄漏漏洞......................................................... 382.37 泛微E-Office 10 /eoffice10/server/public/api/welink/welink-move远程代码执行漏洞...................................................................................................................................................... 392.38 用友GRP-U8 /u8qx/bx_historyDataCheck.jsp SQL注入漏洞............................402.39 用友 U8Cloud /ServiceDispatcherServlet反序列化漏洞...................................... 412.40JumpServer堡垒机 会话回放未授权访问漏洞............................................................. 42 2.41 致远OA前台任意用户密码重置漏洞.................................................................................. 432.42iDocView /html/2word远程代码执行漏洞...................................................................... 442.43JeecgBoot积木报表testConnection JDBC远程代码执行...................................452.44 大华DSS综合管理平台/portal/attachment_downloadByUrlAtt.action路径存在任意文件下载漏洞....