Vulnerabilities > Server-Side Request Forgery (SSRF)

DATE CVE VULNERABILITY TITLE RISK
2017-05-31 CVE-2017-9307 Server-Side Request Forgery (SSRF) vulnerability in Allen Disk Project Allen Disk 1.6
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.
network
low complexity
allen-disk-project CWE-918
4.0
2017-05-18 CVE-2017-9066 Server-Side Request Forgery (SSRF) vulnerability in Wordpress
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
network
low complexity
wordpress debian CWE-918
5.0
2017-05-05 CVE-2017-8794 Server-Side Request Forgery (SSRF) vulnerability in Accellion File Transfer Appliance 80540
An issue was discovered on Accellion FTA devices before FTA_9_12_180.
network
low complexity
accellion CWE-918
6.4
2017-04-24 CVE-2017-3546 Server-Side Request Forgery (SSRF) vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.54/8.55
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework).
network
low complexity
oracle CWE-918
6.4
2017-04-24 CVE-2015-7570 Server-Side Request Forgery (SSRF) vulnerability in Yeager CMS 1.2.1
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/org/adodb_lite/tests/test_datadictionary.php, or libs/org/adodb_lite/tests/test_adodb_lite_sessions.php.
network
low complexity
yeager CWE-918
6.4
2017-04-14 CVE-2016-7051 Server-Side Request Forgery (SSRF) vulnerability in Fasterxml Jackson-Dataformat-Xml
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
network
low complexity
fasterxml CWE-918
5.0
2017-04-06 CVE-2017-7569 Server-Side Request Forgery (SSRF) vulnerability in Vbulletin
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
network
low complexity
vbulletin CWE-918
5.0
2017-04-06 CVE-2017-7566 Server-Side Request Forgery (SSRF) vulnerability in Mybb
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
network
low complexity
mybb CWE-918
4.0
2017-04-06 CVE-2017-6130 Server-Side Request Forgery (SSRF) vulnerability in F5 SSL Intercept Iapp and SSL Orchestrator
F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.
network
f5 CWE-918
5.8
2017-03-27 CVE-2017-7272 Server-Side Request Forgery (SSRF) vulnerability in PHP
PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained.
network
php CWE-918
5.8