CVE-2020-6308: SAP BusinessObjects Business Intelligence Platform – Blind Server-Side Request Forgery

CVE-2020-6308: SAP BusinessObjects Business Intelligence Platform - Blind Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享
CVE-2020-6308: SAP BusinessObjects Business Intelligence Platform – Blind Server-Side Request Forgery
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-6308: SAP BusinessObjects Business IntelligeNCe Platform – Blind Server-Side Request Forgery

漏洞描述

SAP BusinessObjects Business Intelligence Platform (Web Services) 410, 420, and 430 is susceptible to blind server-side request forgery. An attacker can inject arbitrary values as CMS parameters to perform lookups on the internal network, which is otherwise not accessible externally. On successful exploitation, attacker can scan network to determine infrastructure and gather information for further attacks like remote file inclusion, retrieving server files, bypassing firewall, and forcing malicious requests.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享