Rojo 的 “rojo serve” HTTP API(默认端口为 34872)未对 Host/Origin 头部进行验证,因此易受 DNS 重绑定攻击。恶意网页可以在无需用户交互(仅需访问该页面)的情况下,读取所有项目源代码、将恶意代码写入磁盘文件,并通过调用 opener::open() 启动本地程序。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet