Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/handlers/emulators/rfi.py supports Remote File Inclusion emulation
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/mushorg/glastopf/issues/286 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-04-19T08:00:00
Updated: 2024-08-05T07:32:01.763Z
Reserved: 2018-04-19T00:00:00
Link: CVE-2018-10220
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-04-19T08:29:00.407
Modified: 2024-08-05T08:15:21.127
Link: CVE-2018-10220
Redhat
No data.