Lucene search

K
hackeroneOrangeH1:305974
HistoryJan 17, 2018 - 5:30 p.m.

Internet Bug Bounty: Inappropriate URL parsing may cause security risk!

2018-01-1717:30:00
orange
hackerone.com
$1000
25

EPSS

0.002

Percentile

55.1%

Description


The behaviors in parse_url and http_wrap/cURL are different

Original bug report


Note


  • CVE-2017-7189 assigned

Thanks :)

Impact

SSRF