# N/A
## 漏洞概述
mailboxd组件在Synacor Zimbra Collaboration Suite 8.7.x版本中存在XML外部实体注入(XXE)漏洞,具体影响Autodiscover/Autodiscover.xml功能。
## 影响版本
8.7.x版本,低于8.7.11p10
## 漏洞细节
在mailboxd组件中,当处理Autodiscover/Autodiscover.xml时,存在XML外部实体注入(XXE)漏洞。攻击者可以通过构造特定的XML输入利用该漏洞。
## 漏洞影响
攻击者可以利用此漏洞读取敏感文件、执行文件操作或发起DoS攻击,具体取决于配置。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | Zimbra RCE PoC - CVE-2019-9670 XXE/SSRF | https://github.com/rek7/Zimbra-RCE | POC详情 |
2 | Zimbra RCE CVE-2019-9670 | https://github.com/attackgithub/Zimbra-RCE | POC详情 |
3 | 🔥 Arbimz is a python tool created to exploit the vulnerability on Zimbra assigned as CVE-2019-9670. | https://github.com/oppsec/arbimz | POC详情 |
4 | 🕵️ Yet another CVE-2019-9670 exploit, but in Golang. | https://github.com/oppsec/zaber | POC详情 |
5 | CVE-2019-9670 is used to find XXE bug | https://github.com/Cappricio-Securities/CVE-2019-9670 | POC详情 |
6 | None | https://github.com/OracleNep/CVE-2019-9670-DtdFilegeneration | POC详情 |
7 | 🔥 Arbimz is a python tool created to exploit the vulnerability on Zimbra assigned as CVE-2019-9670. | https://github.com/000pp/arbimz | POC详情 |
8 | 🕵️ Yet another CVE-2019-9670 exploit, but in Golang. | https://github.com/000pp/zaber | POC详情 |
9 | Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML external entity injection (XXE) vulnerability via the mailboxd component. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-9670.yaml | POC详情 |
10 | Zimbra XXE Vul,may Control your Server with AdminPort SSRF | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/zimbra-cve-2019-9670-xxe.yml | POC详情 |
标题: Zimbra Security Advisories - Zimbra :: Tech Center -- 🔗来源链接
标签: x_refsource_MISC