Show filters
307 Total Results
Displaying 41-50 of 307
Sort by:
Attacker Value
Unknown
CVE-2020-21649
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method.
0
Attacker Value
Unknown
CVE-2020-21653
Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method.
0
Attacker Value
Unknown
CVE-2021-39867
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server Side Request Forgery (SSRF) attacks.
0
Attacker Value
Unknown
CVE-2021-39894
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit Server Side Request Forgery attacks.
0
Attacker Value
Unknown
CVE-2021-37223
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the target page can be replaced with an SSRF payload to access internal resources or disclose local system files.
0
Attacker Value
Unknown
CVE-2021-37104
Disclosure Date: September 28, 2021 (last updated February 23, 2025)
There is a server-side request forgery vulnerability in HUAWEI P40 versions 10.1.0.118(C00E116R3P3). This vulnerability is due to insufficient validation of parameters while dealing with some messages. A successful exploit could allow the attacker to gain access to certain resource which the attacker are supposed not to do.
0
Attacker Value
Unknown
CVE-2021-40109
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and loads the contents of the file from the redirected-to server. Files of disallowed types can be uploaded.
0
Attacker Value
Unknown
CVE-2021-41385
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF.
0
Attacker Value
Unknown
CVE-2021-41586
Disclosure Date: September 24, 2021 (last updated February 23, 2025)
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the system user password.
0
Attacker Value
Unknown
CVE-2021-41587
Disclosure Date: September 24, 2021 (last updated February 23, 2025)
In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover credentials for other resources.
0