Zimbra Collaboration Suite(ZCS)是美国Zimbra公司的一款开源协同办公套件,它包括WebMail、日历、通信录等。 ZCS 8.7 Patch 1之前版本和8.8.7之前的8.8.x版本中的‘ZmMailMsgView.getAttachmentLinkHtml’函数存在跨站脚本漏洞。远程攻击者可借助邮件附件中的Content-Location包头利用该漏洞注入任意的Web脚本或HTML。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Cross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before 8.7 Patch 1 and 8.8.x before 8.8.7 might allow remote attackers to inject arbitrary web script or HTML via a Content-Location header in an email attachment. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-6882.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2017-18252 | ImageMagick 安全漏洞 | |
| CVE-2018-9053 | Windows Master 安全漏洞 | |
| CVE-2018-9050 | Windows Master 安全漏洞 | |
| CVE-2018-9049 | Windows Master 安全漏洞 | |
| CVE-2018-9048 | Windows Master 安全漏洞 | |
| CVE-2018-9051 | Windows Master 安全漏洞 | |
| CVE-2018-9039 | Octopus Deploy 权限许可和访问控制问题漏洞 | |
| CVE-2018-9032 | D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router 安全漏洞 | |
| CVE-2017-18254 | ImageMagick 信息泄露漏洞 | |
| CVE-2017-18253 | ImageMagick 安全漏洞 | |
| CVE-2018-9040 | Advanced SystemCare Ultimate 安全漏洞 | |
| CVE-2017-18251 | ImageMagick 安全漏洞 | |
| CVE-2017-18250 | ImageMagick 安全漏洞 | |
| CVE-2018-9055 | JasPer 安全漏洞 | |
| CVE-2018-0202 | ClamAV clamscan 安全漏洞 | |
| CVE-2018-0198 | Cisco Unified Communications Manager 信息泄露漏洞 | |
| CVE-2017-12319 | Cisco IOS XE Software Ethernet Virtual Private Network 安全漏洞 | |
| CVE-2017-12310 | Cisco Spark Hybrid Calendar Service 信息泄露漏洞 | |
| CVE-2018-8764 | Roland Gruber Softwareentwicklung LDAP Account Manager 安全漏洞 | |
| CVE-2018-8763 | Roland Gruber Softwareentwicklung LDAP Account Manager 跨站脚本漏洞 |
Showing top 20 of 60 CVEs. View all on vendor page → →
No comments yet