Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Whoogle Search Server Side Request Forgery vulnerability
Vulnerability Description
Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize user-supplied input from the `location` variable and passes it to the `send` method which sends a `GET` request on lines 339-343 in `request.py,` which leads to a server-side request forgery. This issue allows for crafting GET requests to internal and external resources on behalf of the server. For example, this issue would allow for accessing resources on the internal network that the server has access to, even though these resources may not be accessible on the internet. This issue is fixed in version 0.8.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
whoogle-search 代码问题漏洞
Vulnerability Description
whoogle-search是一个应用软件。自托管,没有广告,privacy-respecting元搜索引擎 whoogle-search 0.8.4 之前版本存在代码问题漏洞,该漏洞源于 window端点不会清理用户从location变量提供的输入,并将其传递给send方法,导致服务器端请求伪造。
CVSS Information
N/A
Vulnerability Type
N/A