oss-sec mailing list archives
Re: Re: Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities
From: Florent Daigniere <florent.daigniere () trustmatta com>
Date: Wed, 17 Feb 2016 10:30:32 +0100
On Tue, 2016-02-16 at 17:23 -0500, cve-assign () mitre org wrote:
http://issues.umbraco.org/issue/U4-7457 SSRFthe feedproxy.aspx is used to access the external resources using the URL GET parameter.http://local/Umbraco/feedproxy.aspx?url=http://bobsite/index once you change the URL to the http://local/Umbraco/feedproxy.aspx?url=http://127.0.0.1:80/index, you able to access the localhost application of the server. Using this payload change the port number to perform port scanning of the server. It will be helpful to find the more details of the server. For example: http://local/Umbraco/feedproxy.aspx?url=http://127.0.0.1:25/index http://local/Umbraco/feedproxy.aspx?url=http://127.0.0.1:8080/index If the port number is closed, you will find the error message on the feedproxy.aspx page.Use CVE-2015-8813.
How different is it from CVE-2012-1301 ? Have they re-introduced it? Florent
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities Sandeep Kamble (Feb 16)
- Re: Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities cve-assign (Feb 16)
- Re: Re: Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities Florent Daigniere (Feb 17)
- Re: Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities cve-assign (Feb 17)
- Re: Re: Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities Sandeep Kamble (Feb 17)
- Re: Re: Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities Florent Daigniere (Feb 17)
- Re: Umbraco - The open source ASP.NET CMS Multiple Vulnerabilities cve-assign (Feb 16)