漏洞描述翻译: Cyberdrop-DL 是一个用于多个文件托管平台的大容量异步下载器。在 8.5.0 到 9.14.0 版本中,Pixeldrain 爬虫使用子串主机匹配,而非要求输入主机名必须是 中的精确成员,随后在发起 API 请求时直接复用了该输入主机名。 当配置了 Pixeldrain API 密钥时,如果处理来自攻击者控制的仿冒(lookalike)主机的特制 URL, 会向该主机发送带有 请求头的请求。该 URL 可能通过第三方站点引入,从而触发对其他站点的下载操作,最终导致攻击者获取用户的 Pixe
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cyberdrop-DL | cyberdrop-dl | >= 8.5.0, < 9.14.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet