Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-7796 PoC — Zimbra Collaboration Suite 代码问题漏洞

Source
Associated Vulnerability
Title:Zimbra Collaboration Suite 代码问题漏洞 (CVE-2020-7796)
Description:Zimbra Collaboration Suite(ZCS)是美国Synacor的一款开源协同办公套件。该产品包括WebMail、日历、通信录等。 Zimbra Collaboration Suite (ZCS) 8.8.15 Patch 7之前版本中存在代码问题漏洞。在安装有WebEx zimlet并启用zimlet JSP时,攻击者可借助特制‘argument’参数利用该漏洞实施服务器请求伪造攻击(SSRF)。
Description
Zimbra Collaboration Suite (ZCS) allows remote unauthenticated attackers to cause the product to include content returned by third-party servers and use it as its own code.
File Snapshot

id: zimbra-preauth-ssrf info: name: Zimbra Collaboration Suite - Server-Side Request Forgery au ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.