SSRF on http://www.███████/crossdomain.php via url parameter
Critical
S
Sony
Submitted None
Team Summary
Official summary from Sony
The researcher reported that a Sony endpoint was vulnerable to Local File Inclusion (LFI) and Server-Side Request Forgery (SSRF) vulnerabilities. The researcher used the LFI vulnerability to read sensitive files such as /etc/passwd from the web server. The researcher also demonstrated using the SSRF vulnerability to view EC2 instance metadata, and to retrieve an externally hosted .svg file to execute a reflected Cross-Site Scripting (XSS) attack.
Actions:
Reported by
n0x496n
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Server-Side Request Forgery (SSRF)