Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Another Byte Bites the Dust - How XBOW Turned a Blind SSRF into a File Reading Oracle

Summary

Details how XBOW escalated a blind SSRF in TiTiler into a full arbitrary file read via byte-by-byte exfiltration in a 48-step chain, from OpenAPI recon to the final oracle.
CVSS
9.3
Published
Collected

original ↗

Related coverage

back