→ كل المشاريع

CVE-2021-26855

بواسطة @h4x0r-dz

100

عن هذا المشروع

CVE-2021-26855-PoC PoC exploit code for CVE-2021-26855. Original code was developed by https://github.com/GreyOrder. The original repo was deleted shortly after additional features (user enumeration etc.) were added. Please post a pull request, if you have the latest version. CVE-2021-26855 ssrf simple use of golang exercises Affected version: Exchange Server 2013 is less than CU23 Exchange Server 2016 is less than CU18 Exchange Server 2019 is less than CU7 Conditions of use: This vulnerability is different from previous exchange vulnerabilities. This vulnerability does not require a user identity that can log in. It can obtain internal user resources without authorization. It can be used with CVE-2021-27065 to implement remote command execution. Vulnerability trigger requirements: Vulnerability in the target server The target exchange server must be a load balancing server, that is, two or more servers are used at the same time The target email address. Note that this address needs to be an in-domain email address instead of an email address, there is a difference between the two

من ملف README الخاص بالمشروع على GitHub

النجوم
100
التفريعات
61
آخر تحديث
09/03/2021

أضف هذه الشارة إلى ملف README

أظهر أن مشروعك مُدرج على «صُنع في الجزائر».

Made in Algeria
[![Made in Algeria](https://www.madeinalgeria.dev/badge/cve-2021-26855.svg)](https://www.madeinalgeria.dev/projects/cve-2021-26855)

مشاريع ذات صلة