U-Mail邮件系统普通用户权限getshell漏洞-2

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: U-Mail邮件系统windows版本存在缺陷,导致普通用户getshell ### 详细说明: 环境说明:官网下载windows版最新版,windows server 2003+IIS6搭建、登录邮箱测试时候使用最新版chrome浏览器,需要普通用户登录 漏洞文件: C:\umail\WorldClient\html\client\option\module\o_letterpaper.php 代码: ``` if ( ACTION == "letterpaper-img-upload" ) { $targetFolder = getusercachepath( ); $verifyToken = md5( "unique_salt".$_POST['timestamp'] ); if ( !empty( $_FILES ) || $_POST['token'] == $verifyToken ) { $tempFile = $_FILES['Filedata']['tmp_name']; $targetPath = $targetFolder; $targetFile = rtrim( $targetPath, "/" )."/letterpaper_".$_FILES['Filedata']['name']; $fileTypes = array( "jpg", "jpeg", "gif", "png" ); $fileParts = pathinfo( $_FILES['Filedata']['name'] ); if ( in_array( $fileParts['extension'], $fileTypes ) ) { $handle = opendir( $targetPath ); while ( ( $file = readdir( $handle ) ) !== FALSE ) { if ( !( $file != "." ) && !( $file != ".." ) && strpos( $file, "letterpaper_" ) === FALSE ) { $dir = rtrim( $targetPath, "/" ).DIRECTORY_SEPARATOR.$file; unlink( $dir );...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息