CVE-2021-26855
by @h4x0r-dz
100
About this project
CVE-2021-26855-PoC PoC exploit code for CVE-2021-26855. Original code was developed by https://github.com/GreyOrder. The original repo was deleted shortly after additional features (user enumeration etc.) were added. Please post a pull request, if you have the latest version. CVE-2021-26855 ssrf simple use of golang exercises Affected version: Exchange Server 2013 is less than CU23 Exchange Server 2016 is less than CU18 Exchange Server 2019 is less than CU7 Conditions of use: This vulnerability is different from previous exchange vulnerabilities. This vulnerability does not require a user identity that can log in. It can obtain internal user resources without authorization. It can be used with CVE-2021-27065 to implement remote command execution. Vulnerability trigger requirements: Vulnerability in the target server The target exchange server must be a load balancing server, that is, two or more servers are used at the same time The target email address. Note that this address needs to be an in-domain email address instead of an email address, there is a difference between the two
From the project README on GitHub
- Stars
- 100
- Forks
- 61
- Last push
- 9 Mar 2021
Add this badge to your README
Show that your project is listed on Made in Algeria.
[](https://www.madeinalgeria.dev/projects/cve-2021-26855)