CVE-2017-9355
HIGHSubsonic 6.1.1 - Server-Side Request Forgery via Import Playlist Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9355. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) vulnerability in Subsonic v6.1.1, allowing an attacker to perform SSRF attacks by tricking a user into importing a malicious .XSPF playlist file. The PoC includes a crafted XML payload that triggers an outbound HTTP request to an attacker-controlled server.
Description
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.
Exploits (1)
This exploit demonstrates an XML External Entity (XXE) vulnerability in Subsonic v6.1.1, allowing an attacker to perform SSRF attacks by tricking a user into importing a malicious .XSPF playlist file. The PoC includes a crafted XML payload that triggers an outbound HTTP request to an attacker-controlled server.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N