
Zimbra <9.0.0.p27 RCE
CVE-2022-41352는 취약한
cpio버전 사용으로 인해 Zimbra 메일 서버에서 발생하는 임의 파일 쓰기 취약점입니다.
영향을 받는 Zimbra 버전:
(자세한 내용은 패치 노트를 참조하세요.)
해결 방법:
취약점을 해결하려면 최신 패치(각각 9.0.0.p27 및 8.8.15.p34)를 적용하거나 pax를 설치하고 서버를 다시 시작하세요.
사용 방법:
플래그를 사용하거나 스크립트의 기본 구성을 수동으로 수정할 수 있습니다(맨 위의 구성 블록).
도움말을 보려면 -h를 사용하세요.
$ python cve-2022-41352.py -h
$ vi cve-2022-41352.py
# Change the config items.
$ python cve-2022-41352.py manual
# This will create an attachment that you can then send to the target server.
# The recipient does not necessarily have to exist - if the email with the attachment is parsed by the server the arbitrary file write in cpio will be triggered.
예시:
(위 스크린샷은 이메일 본문에 대한 잘못된 출력을 보여주지만 이는 수정되었습니다.)
데모: