ardzz / CVE-2022-1386

7 stars 3 forks source link

File read problem #1

Open Bozx opened 1 year ago

Bozx commented 1 year ago

I tried a few payloads on the payload section. None of them worked for me. What should i type to gather /etc/passwd? Regards.

ardzz commented 1 year ago

Hi @Bozx , on this vulnerability we can't read file. I also tried by using file:// wrapper and not working. So use this CVE to gain aws creds or other cloud creds by sending request into their meta-data. If you lazy to fuzzing it try to use SSRFmap