jinri,hulianwangshanggongkaileueditorbianjiqiv1.4.3banbendessrfloudongxinxijifenxifuxiancailiao。gailoudongshiboolxingdessrf,chulekeyijinxingneiwangtancewai,yekeyigenjuwebyingyongzhiwenxinxi,jinxingjinyibuceshi。muqian,guanfangyigengxinbanbenxiufuleshangshuloudong。
亚博买球jianyiyonghuguanzhugailoudong,bingjishiyuxiangguanwangzhankaifadanweiquerenshifoushoudaoloudongyingxiang,jinkuaicaiquxiubucuoshi。
漏洞概述
亚博买球ueditorshiyoubaiduwebqianduanyanfabukaifasuojianjisuodefuwenbenwebbianjiqi,juyouqingliang,kedingzhi,zhuzhongyonghutiyandengtedian,kaiyuanjiyumitxieyi,yunxuziyoushiyonghexiugaidaima。
ueditor v1.4.3jiyiqianbanbencunzaissrfloudong。youyuueditorzaiv1.4.3zhiqianmeiyoujiaruduineibuipdexianzhi,suoyizaishiyongzhuaqutupiandegongnengshi,zaochengssrfloudong。gongjizhekeyiliyonggailoudongjinxingneiwangfuwuqidetance,binggenjuneiwangfuwuqidetezheng(ru/jmx-console/images/logo.gif, /tomcat.png),panduanqishiyongdezujian,caicekenengcunzaideloudong,ranhoujinxingjinyibudeshentou。
漏洞危害
亚博买球gongjizhekeliyonggailoudongkejinxingneiwangtancehebufenyingyongshibie,congerjinxingjinyibugongji。
受影响范围
baiduueditor webbianjiqi≦v1.4.3
修复建议
muqian,guanfangyigengxinbanbenxiufuleshangshuloudong,jianyiyonghujishiyuxiangguanwangzhankaifadanweiquerenshifoushoudaoloudongyingxiang,jinkuaicaiquxiubucuoshi。
guanfangcankaolianjie: