Skip to content

Latest commit

 

History

History
24 lines (13 loc) · 935 Bytes

SSRF.md

File metadata and controls

24 lines (13 loc) · 935 Bytes

The SSRF vulnerability exists in dedeCMS v5.7.109

official website:https://www.dedecms.com/

version:5.7.109

Access the dnslog via the rssurl parameter

WPS图片(1)

The Dnslog command is displayed successfully WPS图片(2)

Follow the GetRssLinks() function in the co do.php file

WPS图片(3)

Follow up with the OpenUrl() function

WPS图片(4)

Finding the parse_url() function in the PrivateInit() function is the key to ultimately triggering ssrf

WPS图片(5)