Piattaforme Vulnerabili a SSRF

Reading time: 2 minutes

tip

Impara e pratica il hacking AWS:HackTricks Training AWS Red Team Expert (ARTE)
Impara e pratica il hacking GCP: HackTricks Training GCP Red Team Expert (GRTE) Impara e pratica il hacking Azure: HackTricks Training Azure Red Team Expert (AzRTE)

Supporta HackTricks

Controlla https://blog.assetnote.io/2021/01/13/blind-ssrf-chains/

  • SugarCRM ≤ 14.0.0 – LESS @import injection in /rest/v10/css/preview consente SSRF non autenticato e lettura di file locali.

Less Code Injection Ssrf

tip

Impara e pratica il hacking AWS:HackTricks Training AWS Red Team Expert (ARTE)
Impara e pratica il hacking GCP: HackTricks Training GCP Red Team Expert (GRTE) Impara e pratica il hacking Azure: HackTricks Training Azure Red Team Expert (AzRTE)

Supporta HackTricks