AVideo 24.0 之前的版本中, 函数存在服务器端请求伪造(SSRF)漏洞,该函数未能从 NAT64、6to4 和 Teredo 等 IPv6 过渡地址格式中提取嵌入的 IPv4 地址。未认证的攻击者可以通过 LiveLinks 代理端点绕过 SSRF 防护机制,通过将私有 IPv4 目标编码为过渡地址格式,从而访问内部服务和云元数据端点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet