GestSup 3.2.61 之前的版本存在一个远程代码执行漏洞,该漏洞位于基础 IMAP 连接器处理附件的逻辑中,由于未能正确跳过被阻止的文件扩展名,攻击者可以在未认证的情况下,向被监控的邮箱发送包含 PHP 附件的邮件。这些附件会被写入到可通过 Web 访问的 upload/ticket 目录,并在被访问时执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet