目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-45519 PoC — Zimbra Collaboration Server 安全漏洞

来源
关联漏洞
标题: Zimbra Collaboration Server 安全漏洞 (CVE-2024-45519)
Description:Zimbra Collaboration Server(ZCS)是Zimbra公司的一套电子邮件和协作解决方案。该方案提供电子邮件、联系人、日历、文件共享、社交网络等功能。 Zimbra Collaboration Server存在安全漏洞,该漏洞源于日志服务有时允许未经身份验证的用户执行命令。以下版本受到影响:8.8.15补丁46之前版本、9.0.0补丁41之前版本、10.0.9之前版本和10.1.1之前版本。
Description
CVE-2024-45519 unauthenticated OS commoand Injection in Zimbra prior to 8.8.15***.
介绍
CVE-2024-45519 unauthenticated OS commoand Injection in Zimbra prior to 8.8.15***.


[Downlaod link here](https://bit.ly/3Bjuics)

# Details:
what is Journalling?<br>
Journalling is a process which is used for email compliance or archiving purposes.<br>
`Insecure handling of email data` results in unauthenticated command execution in context of `zimbra` user.<br>
The vulnerability occures in certain condition if journalling is configured `which is not a default configuration`,<br>
as its obvious with the journalling process mostl likely its configured by orginizations.<br>

# About:
Process:<br>
While the rules are set for journalling emails, The income emails are processed by MTA (in zimbra case its Postfix)<br>
when it detects that an email matches the journal rules, then it sends a copy of the email to the PostJournal service<br>
and then the PostJournal captures the email data including header,body.............

A complete deep dive (zimbra.pdf) to undrestand the vulnerable code and bypasses of filters and how we can abuse it to acheive Command Injection
</p>
A python script (CVE-2024-45519.py) which trigger the vulnerability and execute user supplied command in context of the zimbra user
can also execute command on single and multiple targets(IP list) with multi-threading capability.<br>

Shodan Dork: http.favicon.hash:1624375939 <br>
20k Ips are included here (ips.txt)<br>
in time of writting 66k results in shodan.<br>


# Download: [here](https://bit.ly/3Bjuics)
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →