Zimbra Collaboration Server(ZCS)是Zimbra公司的一套电子邮件和协作解决方案。该方案提供电子邮件、联系人、日历、文件共享、社交网络等功能。 Zimbra Collaboration Server存在安全漏洞,该漏洞源于日志服务有时允许未经身份验证的用户执行命令。以下版本受到影响:8.8.15补丁46之前版本、9.0.0补丁41之前版本、10.0.9之前版本和10.1.1之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2024-45519 unauthenticated OS commoand Injection in Zimbra prior to 8.8.15***. | https://github.com/TOB1a3/CVE-2024-45519-PoC | POC Details |
| 2 | None | https://github.com/p33d/CVE-2024-45519 | POC Details |
| 3 | Zimbra - Remote Command Execution (CVE-2024-45519) | https://github.com/Chocapikk/CVE-2024-45519 | POC Details |
| 4 | None | https://github.com/whiterose7777/CVE-2024-45519 | POC Details |
| 5 | None | https://github.com/XiaomingX/cve-2024-45519-poc | POC Details |
| 6 | Zimbra CVE-2024-45519 | https://github.com/sec13b/CVE-2024-45519 | POC Details |
| 7 | SMTP-based vulnerability in the PostJournal service of Zimbra Collaboration Suite that allows unauthenticated attackers to inject arbitrary commands. This vulnerability arises due to improper sanitization of SMTP input, enabling attackers to craft malicious SMTP messages that execute commands under the Zimbra user context. Successful exploitation can lead to unauthorized access, privilege escalation, and potential compromise of the affected system's integrity and confidentiality. | https://github.com/projectdiscovery/nuclei-templates/blob/main/javascript/cves/2024/CVE-2024-45519.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-21530 | 4.5 MEDIUM | Cocoon 安全漏洞 |
| CVE-2024-45186 | FileSender 安全漏洞 | |
| CVE-2024-33210 | FlatPress 安全漏洞 | |
| CVE-2024-33209 | FlatPress 安全漏洞 | |
| CVE-2024-33662 | Portainer 安全漏洞 | |
| CVE-2024-45960 | Zenario CMS 安全漏洞 | |
| CVE-2024-45962 | October CMS 安全漏洞 | |
| CVE-2024-45964 | Zenario CMS 安全漏洞 | |
| CVE-2024-24117 | Ruijie Networks RG-NBS2009G-P 安全漏洞 | |
| CVE-2024-24122 | Yitu 安全漏洞 | |
| CVE-2024-24116 | Ruijie Networks RG-NBS2009G-P 安全漏洞 | |
| CVE-2024-41290 | FlatPress 安全漏洞 | |
| CVE-2024-46626 | Open Solutions For Education OpenSis-Classic 安全漏洞 |
No comments yet