vendor:
HTTPd
by:
5.5
CVSS
MEDIUM
Server Side Request Forgery (SSRF)
918
CWE
Product Name: HTTPd
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
HTTPd Server Side Request Forgery (SSRF) via Vertical Tab (%09) Exploit
The exploit involves using a vertical tab (%09) followed by another URL in the tag. When a victim clicks the link on the error page, they will be redirected to a different destination. The exploit URL format is `http://domain.tld/%09//otherdomain.tld`.
Mitigation:
To mitigate this vulnerability, ensure that user-supplied URLs are properly validated and sanitized. Additionally, consider implementing a whitelist of allowed URLs to restrict potential SSRF attacks.