Vulnerabilities > CVE-2017-14611 - Server-Side Request Forgery (SSRF) vulnerability in Agentejo Cockpit 0.13.0

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
agentejo
CWE-918
critical
exploit available

Summary

SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.

Vulnerable Configurations

Part Description Count
Application
Agentejo
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionCockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery. CVE-2018-9302. Webapps exploit for PHP platform. Tags: Server-Side Request Forgery (SSRF)
fileexploits/php/webapps/44567.txt
idEDB-ID:44567
last seen2018-05-24
modified2018-05-02
platformphp
port80
published2018-05-02
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44567/
titleCockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
typewebapps

Packetstorm