Zimbra是美国Zimbra公司的一套开源的电子邮件协作平台。 Zimbra存在安全漏洞,该漏洞源于其sudo配置允许用户使用任意参数作为根用户执行zmslapd二进制文件。作为其预期功能的一部分,zmslapd可以加载用户定义的配置文件,其中包括so文件形式的插件,导致这些插件也作为根用户执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Synacor | Zimbra Server | 9.0.0.p27 ~ 9.0.0.p27 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet