Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-8813 PoC — Umbraco 安全漏洞

Source
Associated Vulnerability
Title:Umbraco 安全漏洞 (CVE-2015-8813)
Description:Umbraco是丹麦Umbraco公司的一套使用ASP.Net构建,Mysql进行数据存储的内容管理系统(CMS)。该系统支持自定义模板、管理用户、对内容进行权限定义等。 Umbraco 7.4.0之前的版本中的Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs文件中的‘Page_Load’函数存在安全漏洞。远程攻击者可借助‘url’参数利用该漏洞实施服务器端请求伪造攻击。
Description
Umbraco before version 7.4.0 contains a server-side request forgery vulnerability in feedproxy.aspx that allows attackers to send arbitrary HTTP GET requests via http://local/Umbraco/feedproxy.aspx?url=http://127.0.0.1:80/index.
File Snapshot

id: CVE-2015-8813 info: name: Umbraco <7.4.0- Server-Side Request Forgery author: emadshanab ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.