U-Mail邮件系统二次注入3(不鸡肋,可获取管理员密码)

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: U-Mail邮件系统二次注入漏洞,可直接获取管理员密码 ### 详细说明: 版本:最新版v9.8.57 漏洞文件 /client/oab/module/operates.php 代码 ``` if ( ACTION == "save-to-pab" ) { include_once( LIB_PATH."PAB.php" ); $PAB = PAB::getinstance( ); $maillist_id = gss( $_GET['maillist'] ); if ( $maillist_id ) { $member_all = $Maillist->getMemberByMaillistID( $maillist_id, "Mailbox,FullName", 0 ); if ( !$member_all ) { dump_json( array( "status" => TRUE, "message" => "" ) ); } foreach ( $member_all as $member ) { if ( !$PAB->getContactByMail( $user_id, $member['Mailbox'], "contact_id", 0 ) ) { $data = array( "user_id" => $user_id, "fullname" => $member['FullName'],//二次注入 "pref_email" => $member['Mailbox'], "updated" => date( "Y-m-d H:i:s" ) ); $res = $PAB->add_contact( $data, 0 ); if ( !$res ) { dump_json( array( "status" => FALSE, "message" => el( "添加联系人时发生错误,添加失败!", "" ) ) ); } } } } else { $user_ids = gss( $_GET['userlist'] ); $user_ids = id_list_filter( $user_ids );//WooYun-2014-72963 if ( !$user_ids ) { dump_msg(...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息