Vulnerabilities > CVE-2017-14611 - Server-Side Request Forgery (SSRF) vulnerability in Agentejo Cockpit 0.13.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery. CVE-2018-9302. Webapps exploit for PHP platform. Tags: Server-Side Request Forgery (SSRF) |
file | exploits/php/webapps/44567.txt |
id | EDB-ID:44567 |
last seen | 2018-05-24 |
modified | 2018-05-02 |
platform | php |
port | 80 |
published | 2018-05-02 |
reporter | Exploit-DB |
source | https://www.exploit-db.com/download/44567/ |
title | Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery |
type | webapps |
Packetstorm
data source https://packetstormsecurity.com/files/download/147077/cockpitcms0130-ssrf.txt id PACKETSTORM:147077 last seen 2018-04-08 published 2018-04-06 reporter Jiawang Zhang source https://packetstormsecurity.com/files/147077/Cockpit-CMS-0.13.0-Server-Side-Request-Forgery.html title Cockpit CMS 0.13.0 Server Side Request Forgery data source https://packetstormsecurity.com/files/download/147412/cockpitcms055-ssrf.txt id PACKETSTORM:147412 last seen 2018-05-07 published 2018-04-28 reporter Jiawang Zhang source https://packetstormsecurity.com/files/147412/Cockpit-CMS-0.5.5-Server-Side-Request-Forgery.html title Cockpit CMS 0.5.5 Server-Side Request Forgery