CVE-2021-47703
HIGHOpenBMCS 2.4 phpQuery.php - ip Parameter Server-Side Request Forgery
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47703. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated SSRF vulnerability in OpenBMCS 2.4 by sending a crafted POST request to '/php/query.php' with a manipulated 'ip' parameter, forcing the server to make arbitrary HTTP requests. The provided HTTP request and response confirm the vulnerability's existence and behavior.
Description
OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' parameter to force the application to make an HTTP request to an arbitrary destination host.
Exploits (1)
This exploit demonstrates an unauthenticated SSRF vulnerability in OpenBMCS 2.4 by sending a crafted POST request to '/php/query.php' with a manipulated 'ip' parameter, forcing the server to make arbitrary HTTP requests. The provided HTTP request and response confirm the vulnerability's existence and behavior.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N