CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery

CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享
CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 – Remote File Inclusion/Server-Side Request Forgery

漏洞描述

Onair2 < 3.9.9.2 and KenthaRadio < 2.0.2 have exposed proxy functionality to unauthenticated users. Sending requests to this proxy functionality will have the web server fetch and display the content from any URI, allowing remote file inclusion and server-side request forgery.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享