Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Zimbra Collaboration 命令注入漏洞
Vulnerability Description
Zimbra Collaboration是Zimbra公司的一套协作与通信平台。 Zimbra Collaboration 10.1.20之前版本存在命令注入漏洞,该漏洞源于SNMP通知处理期间未正确清理不可信输入,在安装zimbra-snmp包并启用SNMP通知时,未经身份验证的攻击者可以发送特制的SMTP请求,可能导致以Zimbra用户身份执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A