Microsoft UFO是美国Microsoft公司的一款Web服务器。 Microsoft UFO 3.0.8之前版本存在服务端请求伪造漏洞,该漏洞源于ufo/utils/url_security.py中的_is_blocked_ip函数未阻止NAT64、6to4和Teredo前缀,且未重新检查嵌入的IPv4目标,可能导致未经身份验证的远程攻击者绕过SSRF防护,访问云元数据、内部服务或本地主机。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73299 | 10.0 CRITICAL | Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunj |
| CVE-2026-73296 | 9.4 CRITICAL | Microsoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and |
| CVE-2026-73298 | 8.7 HIGH | Microsoft Container Migration Solution Accelerator: Authenticated IDOR allowing read/write |
No comments yet