Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability
# CVE-2022-41352 PoC
## How does this detection method work?
As stated on the advisories an issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0, the template looks at the following versions:
```
- "8.8.15"
- "9.0"
```
## How do I run this script?
1. Download Nuclei from [here](https://github.com/projectdiscovery/nuclei)
2. Copy the template to your local system
3. Run the following command: `nuclei -u https://yourHost.com -t template.yaml`
## References
- https://nvd.nist.gov/vuln/detail/cve-2022-41352
- http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html#
- https://forums.zimbra.org/viewtopic.php?t=71153&p=306532
## Disclaimer
Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view