# Icewarp Email Server 12.3.0.1 unlimited_file_upload
https://nvd.nist.gov/vuln/detail/CVE-2020-14065
## Introduction :
### first step: login to your account and then change your profile picture.
### second step: send request to intruder, and add posiotion like below.

### third step: send request to intruder, and add posiotion like below.

### forth step: start attack.
result: Look at the responses, as you can see all of files has been uploaded and you can access the file. the file upload location pattern is "upload_date-folder(random number)/file(random number)" Look at below image.

[4.0K] /data/pocs/45f15cabdd6c4f9e6d3eef519a14628e5c8249d4
├── [ 929] README.md
├── [ 83K] unlimi2.PNG
├── [ 48K] unlimit1.PNG
└── [114K] unlimited upload file-1 - Copy.PNG
0 directories, 4 files