Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories | vendor advisory |
https://wiki.zimbra.com/wiki/Security_Center | vendor advisory |
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P24 | release notes vendor advisory |
http://packetstormsecurity.com/files/168146/Zimbra-Zip-Path-Traversal.html | exploit vdb entry third party advisory |