U-mail...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 疯狗、 xsser finger求打雷 ### 详细说明: 注:一个getshell重复 http://wooyun.org/bugs/wooyun-2014-059954 疯狗、 xsser finger求打雷 1、信息泄露 (phpinfo信息泄露) http://www.xxx.com/webmail/client/mail/index.php?module=test&action=info phpinfo()信息泄露 ``` 其中源码如下:WorldClient\html\client\mail\module\info.php if ( !defined( "PRELOAD_OK" ) ) { exit( "error" ); } require_once( LIB_PATH."Mailbox.php" ); require_once( LIB_PATH."Widget.php" ); $Mailbox = Mailbox::getinstance( ); $Widget = Widget::getinstance( ); $Domain = Domain::getinstance( ); $email = get_session( "email" ); $user_id = get_session( "user_id" ); $domain_id = get_session( "domain_id" ); phpinfo( ); ?> ``` Exp: http://mail.comingchina.com/webmail/client/mail/index.php?module=test&action=info 官方测试截图如下: [<img src="https://images.seebug.org/upload/201405/25121849661f2c77dd11bc530d8ea74ad598cc27.jpg" alt="5)4IS377`{(%C793DC[3FQ0.jpg" width="600"...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息