CVE-2018-3167: Oracle E-Business Suite – Blind SSRF

CVE-2018-3167: Oracle E-Business Suite - Blind SSRF-渗透云记 - 专注于网络安全与技术分享
CVE-2018-3167: Oracle E-Business Suite – Blind SSRF
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2018-3167: oracle E-Business Suite – Blind ssrf

漏洞描述

Oracle E-Business Suite, Application Management Pack component (User Monitoring subcomponent), is susceptible to blind server-side request forgery. An attacker with network access via HTTP can gain read access to a subset of data, connect to internal services like HTTP-enabled databases, or perform post requests towards internal services which are not intended to be exposed. Affected supported versions are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享