loopback-address-bypass

1 article
Sort: New Top Best
clear filter
0
bug-bounty

A Server-Side Request Forgery (SSRF) vulnerability was discovered in DownNotifier that allowed enumeration of local services through XSPA attacks by bypassing loopback address filters using the 0.0.0.0 address. The vulnerability enabled detection of running services like FTP and HTTP on the server.

DownNotifier downnotifier.com OpenBugBounty PayloadsAllTheThings mqt
m-q-t.github.io · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details