目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-73570 PoC — Zimbra Collaboration 命令注入漏洞

来源
关联漏洞
标题: Zimbra Collaboration 命令注入漏洞 (CVE-2026-73570)
Description:Zimbra Collaboration是Zimbra公司的一套协作与通信平台。 Zimbra Collaboration 10.1.20之前版本存在命令注入漏洞,该漏洞源于SNMP通知处理期间未正确清理不可信输入,在安装zimbra-snmp包并启用SNMP通知时,未经身份验证的攻击者可以发送特制的SMTP请求,可能导致以Zimbra用户身份执行任意操作系统命令。
Description
Zimbra Collaboration Suite (ZCS) before version 10.1.20 is vulnerable to OS command injection in the SNMP notification processing due to improper input sanitization. According to the NVD, when SNMP notifications are enabled and the zimbra-snmp package is installed, an unauthenticated attacker can inject arbitrary commands using crafted SMTP requests that result in malicious log entries. The swatchdog service monitors the log, and upon matching a pattern, passes the log content to zmsnmptrapd, which unsafely uses the Perl backtick operator to execute commands. This can ultimately allow remote attackers to execute arbitrary operating system commands as the zimbra user. Active exploitation of this vulnerability has been observed in the wild, as confirmed by CERT Polska and CISA.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →