Exploit IceWarp Universal WebMail - '/mail/include.html' Crafted HTTP_USER_AGENT Arbitrary File Access

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
26984
Проверка EDB
  1. Пройдено
Автор
TAN CHEW KEONG
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2005-4559
Дата публикации
2005-12-27
Код:
source: https://www.securityfocus.com/bid/16069/info
    
IceWarp Universal WebMail is prone to multiple input-validation vulnerabilities. Deerfield VisNetic Mail Server and Merak Mail Server integrate IceWarp Universal WebMail into their suites.
    
An attacker can exploit these issues to include arbitrary local or remote files containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
    
Additionally, an attacker can exploit these issues to obtain the contents of local files.
    
Merak Mail Server 8.3.0.r and VisNetic MailServer 8.3.0 build 1 are affected by these issues.
    
UPDATE (July 30, 2007): Symantec has confirmed that this issue is being actively exploited in the wild.

http://example.com:32000/mail/index.html?/mail/index.html?default_layout=OUTLOOK2003&layout_settings[OUTLOOK2003]=test;[file]%00;2
 
Источник
www.exploit-db.com

Похожие темы